Bugzilla Default HTML Template Cross-Site Scripting Vulnerabilities
BID:6868
Info
Bugzilla Default HTML Template Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 6868 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0602 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
Mozilla Bugzilla 2.17.3 Mozilla Bugzilla 2.17.1 Mozilla Bugzilla 2.17 Mozilla Bugzilla 2.16.2 Mozilla Bugzilla 2.16.1 Mozilla Bugzilla 2.16 |
| Not Vulnerable: |
Mozilla Bugzilla 2.17.4 Mozilla Bugzilla 2.16.3 |
Discussion
Bugzilla Default HTML Template Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting vulnerabilities exist in the default HTML templates for Bugzilla. User-supplied input is not sanitized of HTML and script code before being output by Bugzilla. Hostile script code and HTML could be passed through Bugzilla and interpreted in the browser of a web user who visits a site hosting Bugzilla.
Multiple cross-site scripting vulnerabilities exist in the default HTML templates for Bugzilla. User-supplied input is not sanitized of HTML and script code before being output by Bugzilla. Hostile script code and HTML could be passed through Bugzilla and interpreted in the browser of a web user who visits a site hosting Bugzilla.
References
Bugzilla Default HTML Template Cross-Site Scripting Vulnerabilities
References:
References:
- Bugzilla Homepage (Mozilla)