Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-0916

Опубликовано: 28 фев. 2006
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

edgy

not-affected

feisty

not-affected

gutsy

not-affected

hardy

not-affected

intrepid

not-affected

jaunty

not-affected

karmic

not-affected

upstream

released

2.20.1

Показывать по

Ссылки на источники

EPSS

Процентиль: 72%
0.00743
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 19 лет назад

Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.

debian
больше 19 лет назад

Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences i ...

github
больше 3 лет назад

Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.

EPSS

Процентиль: 72%
0.00743
Низкий

7.5 High

CVSS2