|
|
Log in / Subscribe / Register

bugzilla: security bypass/cross-site scripting

Package(s):bugzilla CVE #(s):CVE-2012-0466 CVE-2012-0465
Created:May 1, 2012 Updated:May 2, 2012
Description: From the CVE entries:

template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins, which allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive bug information via a crafted web page. (CVE-2012-0466)

Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote attackers to bypass the lockout policy via a series of authentication requests with (1) different IP address strings in this header or (2) a long string in this header. (CVE-2012-0465)

Alerts:
Fedora FEDORA-2012-6396 bugzilla 2012-05-01
Fedora FEDORA-2012-6368 bugzilla 2012-05-01

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds