Bugzilla quips Feature Cross Site Scripting Vulnerability
BID:6257
Info
Bugzilla quips Feature Cross Site Scripting Vulnerability
| Bugtraq ID: | 6257 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2002 12:00AM |
| Updated: | Nov 26 2002 12:00AM |
| Credit: | This vulnerability was announced in a Bugzilla advisory. |
| Vulnerable: |
Mozilla Bugzilla 2.17 Mozilla Bugzilla 2.16.1 Mozilla Bugzilla 2.16 Mozilla Bugzilla 2.14.4 Mozilla Bugzilla 2.14.3 Mozilla Bugzilla 2.14.2 Mozilla Bugzilla 2.14.1 Mozilla Bugzilla 2.14 Mozilla Bugzilla 2.12 Mozilla Bugzilla 2.10 |
| Not Vulnerable: |
Mozilla Bugzilla 2.17.1 Mozilla Bugzilla 2.16.2 Mozilla Bugzilla 2.14.5 |
Discussion
Bugzilla quips Feature Cross Site Scripting Vulnerability
A cross site scripting vulnerability has been reported for Bugzilla. This vulnerability only affects users who have the 'quips' feature enabled.
Reportedly, Bugzilla does not sufficiently sanitize user-supplied input that is used in the quips feature. As a result, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of the website running Bugzilla.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software.
A cross site scripting vulnerability has been reported for Bugzilla. This vulnerability only affects users who have the 'quips' feature enabled.
Reportedly, Bugzilla does not sufficiently sanitize user-supplied input that is used in the quips feature. As a result, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of the website running Bugzilla.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software.