Page 11 of 72 results (0.006 seconds)

CVSS: 7.5EPSS: 0%CPEs: 25EXPL: 2

post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product. • http://marc.info/?l=bugtraq&m=111592031902962&w=2 http://secunia.com/advisories/15338 http://www.bugzilla.org/security/2.16.8 http://www.osvdb.org/16426 https://bugzilla.mozilla.org/show_bug.cgi?id=287109 https://exchange.xforce.ibmcloud.com/vulnerabilities/42797 •

CVSS: 5.0EPSS: 0%CPEs: 25EXPL: 3

Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history. • http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=001040 http://marc.info/?l=bugtraq&m=111592031902962&w=2 http://secunia.com/advisories/15338 http://www.osvdb.org/16427 http://www.securityfocus.com/bid/13605 http://www.vupen.com/english/advisories/2005/0533 https://bugzilla.mozilla.org/show_bug.cgi?id=287436 •

CVSS: 4.3EPSS: 1%CPEs: 18EXPL: 0

Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter. • http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=001040 http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html http://www.mikx.de/index.php?p=6 http://www.securityfocus.com/bid/12154 https://bugzilla.mozilla.org/show_bug.cgi?id=272620 https://exchange.xforce.ibmcloud.com/vulnerabilities/18728 •

CVSS: 5.0EPSS: 0%CPEs: 25EXPL: 0

process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter. • http://marc.info/?l=bugtraq&m=109872095201238&w=2 https://bugzilla.mozilla.org/show_bug.cgi?id=252638 https://exchange.xforce.ibmcloud.com/vulnerabilities/17840 •

CVSS: 5.0EPSS: 0%CPEs: 26EXPL: 0

show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information. • http://marc.info/?l=bugtraq&m=109872095201238&w=2 http://www.securityfocus.com/bid/11511 https://bugzilla.mozilla.org/show_bug.cgi?id=263780 https://exchange.xforce.ibmcloud.com/vulnerabilities/17841 •