|
|
| |
|
| |
bugzilla: cross-site scripting
| Package(s): | bugzilla |
CVE #(s): | CVE-2013-0785
CVE-2013-0786
|
| Created: | March 18, 2013 |
Updated: | March 20, 2013 |
| Description: |
From the Bugzilla advisory:
* When viewing a bug report, a bug ID containing random code is not
correctly sanitized in the HTML page if the specified page format
is invalid. This can lead to XSS.
* When running a query in debug mode, it is possible to determine if
a given confidential field value (such as a product name) exists.
Bugzilla 4.1 and newer are not affected by this issue. |
| Alerts: |
|
( Log in to post comments)
|
|
|