CVE-2012-4189
Bugzilla Cross Site Request Forgery / Cross Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as demonstrated by the Version field.
Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en Bugzilla v4.1.x y v4.2.x antes de v4.2.4, v4.3.x y v4.4.x antes y v4.4rc1, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de un valor de campo que no se maneja adecuadamente durante la construcción de un informe tabular, como se demuestra usando el campo 'Version'.
Multiple cross site scripting and cross site request forgery vulnerabilities have been discovered and addressed in various versions of Bugzilla.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-08-08 CVE Reserved
- 2012-11-16 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=790296 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.bugzilla.org/security/3.6.11 | 2013-12-13 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2013:066 | 2013-12-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.1 Search vendor "Mozilla" for product "Bugzilla" and version "4.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.1.1 Search vendor "Mozilla" for product "Bugzilla" and version "4.1.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.1.2 Search vendor "Mozilla" for product "Bugzilla" and version "4.1.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.1.3 Search vendor "Mozilla" for product "Bugzilla" and version "4.1.3" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.2 Search vendor "Mozilla" for product "Bugzilla" and version "4.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.2 Search vendor "Mozilla" for product "Bugzilla" and version "4.2" | rc1 |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.2 Search vendor "Mozilla" for product "Bugzilla" and version "4.2" | rc2 |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.2.1 Search vendor "Mozilla" for product "Bugzilla" and version "4.2.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.2.2 Search vendor "Mozilla" for product "Bugzilla" and version "4.2.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.2.3 Search vendor "Mozilla" for product "Bugzilla" and version "4.2.3" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.3 Search vendor "Mozilla" for product "Bugzilla" and version "4.3" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.3.1 Search vendor "Mozilla" for product "Bugzilla" and version "4.3.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.3.2 Search vendor "Mozilla" for product "Bugzilla" and version "4.3.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Bugzilla Search vendor "Mozilla" for product "Bugzilla" | 4.3.3 Search vendor "Mozilla" for product "Bugzilla" and version "4.3.3" | - |
Affected
|