bugzilla - cross site scripting
| Package(s): | bugzilla |
CVE #(s): | |
| Created: | December 30, 2002 |
Updated: | January 1, 2003 |
| Description: |
A cross site scripting vulnerability has been reported for Bugzilla, a
web-based bug tracking system. Bugzilla does not properly sanitize
any input submitted by users. As a result, it is possible for a
remote attacker to create a malicious link containing script code
which will be executed in the browser of a legitimate user, in the
context of the website running Bugzilla. This issue may be exploited
to steal cookie-based authentication credentials from legitimate users
of the website running the vulnerable software.
This vulnerability only affects users who have the 'quips' feature
enabled and who upgraded from version 2.10. |
| Alerts: |
|