CVE-2004-1061 Information
Feb 14, 2021
cve
Description
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18 including 2.16.x before 2.16.11 allows remote attackers to inject arbitrary HTML and web script via forced error messages as demonstrated using the action parameter.
Reference
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=001040 http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html http://www.mikx.de/index.php?p=6 http://www.securityfocus.com/bid/12154 https://bugzilla.mozilla.org/show_bug.cgi?id=272620 https://exchange.xforce.ibmcloud.com/vulnerabilities/18728
Share on: