Page 14 of 125 results (0.015 seconds)

CVSS: 4.3EPSS: 2%CPEs: 5EXPL: 0

Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers. NOTE: this issue is not in Bugzilla itself, but rather due to design or documentation inconsistencies within RSS, or implementation vulnerabilities in RSS readers. While this issue normally would not be included in CVE, it is being identified since the Bugzilla developers have addressed it. Bugzilla 2.20rc1 hasta la versión 2.20 y 2.21.1, cuando utiliza RSS 1.0, permite a atacantes remotos llevar a cabo ataques de XSS a través de un elemento del título con secuencias HTML codificadas tales como ">", que son descodificadas automáticamente por algunos lectores RSS. NOTA: este problema no está en sí mismo en Bugzilla, sino más bien debido a su diseño o inconsistencias de documentación entre RSS, o vulnerabilidades de implementación en lectores RSS. • http://marc.info/?l=bugtraq&m=112818466125484&w=2 http://secunia.com/advisories/18979 http://www.bugzilla.org/security/2.18.4 http://www.osvdb.org/23379 https://bugzilla.mozilla.org/show_bug.cgi?id=313441 https://exchange.xforce.ibmcloud.com/vulnerabilities/24820 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error. • http://www.vupen.com/english/advisories/2006/0692 https://bugzilla.mozilla.org/show_bug.cgi?id=313441 •

CVSS: 5.5EPSS: 0%CPEs: 22EXPL: 1

SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi. • http://secunia.com/advisories/18979 http://www.osvdb.org/23378 http://www.securityfocus.com/archive/1/425584/100/0/threaded http://www.securityfocus.com/bid/16738 http://www.vupen.com/english/advisories/2006/0692 https://bugzilla.mozilla.org/show_bug.cgi?id=312498 https://exchange.xforce.ibmcloud.com/vulnerabilities/24819 •

CVSS: 5.5EPSS: 0%CPEs: 15EXPL: 1

Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error. • http://www.securityfocus.com/archive/1/425584/100/0/threaded http://www.vupen.com/english/advisories/2006/0692 https://bugzilla.mozilla.org/show_bug.cgi?id=312498 https://exchange.xforce.ibmcloud.com/vulnerabilities/42802 • CWE-20: Improper Input Validation •

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain. • http://secunia.com/advisories/18979 http://securityreason.com/securityalert/464 http://www.securityfocus.com/archive/1/425584/100/0/threaded http://www.securityfocus.com/bid/16745 http://www.vupen.com/english/advisories/2006/0692 https://bugzilla.mozilla.org/show_bug.cgi?id=325079 https://exchange.xforce.ibmcloud.com/vulnerabilities/24821 •