Bugzilla Cross Site Scripting and Security Bypass Vulnerabilities
BID:51213
Info
Bugzilla Cross Site Scripting and Security Bypass Vulnerabilities
| Bugtraq ID: | 51213 |
| Class: | Unknown |
| CVE: |
CVE-2011-3657 CVE-2011-3667 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 30 2011 12:00AM |
| Updated: | Apr 13 2015 09:26PM |
| Credit: | Byron Jones, Fr?d?ric Buclin, Gervase Markham, David Lawrence, RedTeam Pentesting, Reed Loden, Max Kanat-Alexander, Mario Gomes |
| Vulnerable: |
Mozilla Bugzilla 4.1.3 Mozilla Bugzilla 4.1.1 Mozilla Bugzilla 4.0.2 Mozilla Bugzilla 3.7.2 Mozilla Bugzilla 3.7.1 Mozilla Bugzilla 3.6.6 Mozilla Bugzilla 3.6.4 Mozilla Bugzilla 3.6.1 Mozilla Bugzilla 3.5.3 Mozilla Bugzilla 3.5.2 Mozilla Bugzilla 3.5.1 Mozilla Bugzilla 3.4.12 Mozilla Bugzilla 3.4.10 Mozilla Bugzilla 3.4.7 Mozilla Bugzilla 3.4.6 Mozilla Bugzilla 3.4.5 Mozilla Bugzilla 3.4.4 Mozilla Bugzilla 3.4.3 Mozilla Bugzilla 3.4.2 Mozilla Bugzilla 3.4.1 Mozilla Bugzilla 3.3.4 Mozilla Bugzilla 3.3.3 Mozilla Bugzilla 3.3.2 Mozilla Bugzilla 3.3.1 Mozilla Bugzilla 3.2.10 Mozilla Bugzilla 3.2.7 Mozilla Bugzilla 3.2.6 Mozilla Bugzilla 3.2.5 Mozilla Bugzilla 3.2.4 Mozilla Bugzilla 3.2.3 Mozilla Bugzilla 3.2.2 Mozilla Bugzilla 3.2.1 Mozilla Bugzilla 3.1.4 Mozilla Bugzilla 3.1.3 Mozilla Bugzilla 3.1.2 Mozilla Bugzilla 3.1.1 Mozilla Bugzilla 3.1 Mozilla Bugzilla 3.0.11 Mozilla Bugzilla 3.0.10 Mozilla Bugzilla 3.0.9 Mozilla Bugzilla 3.0.8 Mozilla Bugzilla 3.0.7 Mozilla Bugzilla 3.0.6 Mozilla Bugzilla 3.0.5 Mozilla Bugzilla 3.0.4 Mozilla Bugzilla 3.0.2 Mozilla Bugzilla 3.0.1 Mozilla Bugzilla 3.0 Mozilla Bugzilla 2.23.4 Mozilla Bugzilla 2.23.3 Mozilla Bugzilla 2.23.2 Mozilla Bugzilla 2.22.7 Mozilla Bugzilla 2.22.6 Mozilla Bugzilla 2.22.5 Mozilla Bugzilla 2.22.4 Mozilla Bugzilla 2.22.3 Mozilla Bugzilla 2.22.2 Mozilla Bugzilla 2.22.1 Mozilla Bugzilla 2.21.2 Mozilla Bugzilla 2.21.1 Mozilla Bugzilla 2.21 Mozilla Bugzilla 2.20.7 Mozilla Bugzilla 2.20.6 Mozilla Bugzilla 2.20.5 Mozilla Bugzilla 2.20.4 Mozilla Bugzilla 2.20.3 Mozilla Bugzilla 2.20.2 Mozilla Bugzilla 2.20.1 Mozilla Bugzilla 2.20 rc2 Mozilla Bugzilla 2.20 rc1 Mozilla Bugzilla 2.19.3 Mozilla Bugzilla 2.19.2 Mozilla Bugzilla 2.19.1 Mozilla Bugzilla 2.19 Mozilla Bugzilla 2.18.6 Mozilla Bugzilla 2.18.5 Mozilla Bugzilla 2.18.4 Mozilla Bugzilla 2.18.3 Mozilla Bugzilla 2.18.2 Mozilla Bugzilla 2.18.1 Mozilla Bugzilla 2.18 rc3 Mozilla Bugzilla 2.18 rc2 Mozilla Bugzilla 2.18 rc1 Mozilla Bugzilla 2.17.7 Mozilla Bugzilla 2.17.6 Mozilla Bugzilla 2.17.5 Mozilla Bugzilla 2.17.4 Mozilla Bugzilla 2.17.3 Mozilla Bugzilla 2.17.2 Mozilla Bugzilla 2.17.1 Mozilla Bugzilla 2.9 Mozilla Bugzilla 2.8 Mozilla Bugzilla 2.6 Mozilla Bugzilla 2.4 Mozilla Bugzilla 3.7.3 Mozilla Bugzilla 3.7.2 Mozilla Bugzilla 3.6.3 Mozilla Bugzilla 3.6.2 Mozilla Bugzilla 3.6 Mozilla Bugzilla 3.4.9 Mozilla Bugzilla 3.4.8 Mozilla Bugzilla 3.4 rc1 Mozilla Bugzilla 3.4 Mozilla Bugzilla 3.2rc2 Mozilla Bugzilla 3.2rc1 Mozilla Bugzilla 3.2.9 Mozilla Bugzilla 3.2.8 Mozilla Bugzilla 3.2 Mozilla Bugzilla 2.22 RC1 Mozilla Bugzilla 2.22 Mozilla Bugzilla 2.20 |
| Not Vulnerable: |
Mozilla Bugzilla 4.0.3 Mozilla Bugzilla 3.6.7 Mozilla Bugzilla 3.4.13 Mozilla Bugzilla 4.2rc1 |
Discussion
Bugzilla Cross Site Scripting and Security Bypass Vulnerabilities
Bugzilla is prone to the following vulnerabilities:
1. A security-bypass vulnerability.
2. A cross-site scripting vulnerability.
Successfully exploiting these issues may allow an attacker to bypass certain security restrictions, execute arbitrary script code in the browser of an unsuspecting user, steal cookie-based authentication credentials, and perform certain administrative actions in the vulnerable application.
Bugzilla is prone to the following vulnerabilities:
1. A security-bypass vulnerability.
2. A cross-site scripting vulnerability.
Successfully exploiting these issues may allow an attacker to bypass certain security restrictions, execute arbitrary script code in the browser of an unsuspecting user, steal cookie-based authentication credentials, and perform certain administrative actions in the vulnerable application.
Exploit / POC
Bugzilla Cross Site Scripting and Security Bypass Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Bugzilla Cross Site Scripting and Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Bugzilla Cross Site Scripting and Security Bypass Vulnerabilities
References:
References:
- Bugzilla Homepage (Bugzilla)
- 4.1.3, 4.0.2, 3.6.6, and 3.4.12 Security Advisory (Bugzilla)
- Bug 697699 - (CVE-2011-3657) [SECURITY] XSS when viewing new charts or tabular a (Bugzilla)
- Bug 697699 - (CVE-2011-3657) [SECURITY] XSS when viewing new charts or tabular a (Bugzilla)
- Bug 711714 - (CVE-2011-3667) [SECURITY] The User.offer_account_by_email WebServi (Bugzilla)
- Bugzilla: Cross-Site Scripting in Chart Generator (RedTeam Pentesting GmbH)