Описание
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2004-1061
- https://bugzilla.mozilla.org/show_bug.cgi?id=272620
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18728
- http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=001040
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html
- http://www.mikx.de/index.php?p=6
- http://www.securityfocus.com/bid/12154
EPSS
CVE ID
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, incl ...
EPSS