Show filters
34 Total Results
Displaying 31-34 of 34
Sort by:
Attacker Value
Unknown
CVE-2010-4567
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2) data: URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the URL (aka bug_file_loc) field.
0
Attacker Value
Unknown
CVE-2011-0048
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 creates a clickable link for a (1) javascript: or (2) data: URI in the URL (aka bug_file_loc) field, which allows remote attackers to conduct cross-site scripting (XSS) attacks against logged-out users via a crafted URI.
0
Attacker Value
Unknown
CVE-2010-3764
Disclosure Date: November 05, 2010 (last updated October 04, 2023)
The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL.
0
Attacker Value
Unknown
CVE-2010-3172
Disclosure Date: November 05, 2010 (last updated October 04, 2023)
CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.
0