Bugzilla quips Feature跨站脚本漏洞

漏洞信息详情

Bugzilla quips Feature跨站脚本漏洞

漏洞简介

Mozilla Bugzilla 2.10至2.17版本的quips特征存在跨站脚本(XSS)漏洞。远程攻击者可以借助\”show all quips\”页面注入任意web脚本或HTML。

漏洞公告

Debian has released fixes which address this issue. It should be noted that this issue only affects those Debian users who have upgraded from version 2.10, which isn’t provided through Debian. Fixes are provided for Debian users who may have installed Bugzilla 2.10.
Patches are available for Bugzilla 2.14.4 and 2.16.1. Bugzilla 2.17 users are advised to obtain a patch via CVS. Detailed information is available in the referenced message.
Fixes are available:
Mozilla Bugzilla 2.10

Mozilla Bugzilla 2.14

Mozilla Bugzilla 2.14.1

Mozilla Bugzilla 2.14.2

Mozilla Bugzilla 2.14.3

Mozilla Bugzilla 2.14.4

Mozilla Bugzilla 2.16

Mozilla Bugzilla 2.16.1

Mozilla Bugzilla 2.17

参考网址

来源: XF
名称: bugzilla-quips-xss(10707)
链接:http://xforce.iss.net/xforce/xfdb/10707

来源: BID
名称: 6257
链接:http://www.securityfocus.com/bid/6257

来源: bugzilla.mozilla.org
链接:http://bugzilla.mozilla.org/show_bug.cgi?id=179329

来源: DEBIAN
名称: DSA-218
链接:http://www.debian.org/security/2002/dsa-218

来源: BUGTRAQ
名称: 20021126 XSS vulnerability in Bugzilla if upgraded from 2.10 or earlier
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=103837886416560&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享