Page 15 of 72 results (0.002 seconds)

CVSS: 7.5EPSS: 0%CPEs: 9EXPL: 0

The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file. Los scripts .htaccess por defecto en Bugzilla 2.14.x anteriores a 2.14.5, 2.16.x anteriores a 2.16.2, y 2.17.x anteriores a 2.17.3 no bloquean el acceso a copias de seguridad del fichero localconfig que son hechas por editores como vi y Emacs, lo que podría permitir a atacantes remotos obtener una contraseña de la base de datos accediendo directamente al fichero copia de seguridad. • http://marc.info/?l=bugtraq&m=104154319200399&w=2 http://www.debian.org/security/2003/dsa-230 http://www.iss.net/security_center/static/10970.php http://www.osvdb.org/6351 http://www.securityfocus.com/bid/6501 •

CVSS: 4.3EPSS: 0%CPEs: 28EXPL: 0

Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page. • http://bugzilla.mozilla.org/show_bug.cgi?id=179329 http://marc.info/?l=bugtraq&m=103837886416560&w=2 http://www.debian.org/security/2002/dsa-218 http://www.securityfocus.com/bid/6257 https://exchange.xforce.ibmcloud.com/vulnerabilities/10707 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •