Page 8 of 72 results (0.004 seconds)

CVSS: 6.8EPSS: 0%CPEs: 24EXPL: 0

21 Jul 2004 — Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter. Múltiples vulnerabilidades de secuencias de órdenes en sitios cruzados (XSS) en (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5)... • http://bugzilla.mozilla.org/show_bug.cgi?id=235265 •

CVSS: 6.1EPSS: 0%CPEs: 28EXPL: 0

31 Dec 2002 — Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page. • http://bugzilla.mozilla.org/show_bug.cgi?id=179329 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •