漏洞信息详情
Bugzilla quips Feature跨站脚本漏洞
- CNNVD编号:CNNVD-200212-615
- 危害等级: 中危
- CVE编号:
CVE-2002-2260
- 漏洞类型:
跨站脚本
- 发布时间:
2002-12-31
- 威胁类型:
远程
- 更新时间:
2002-12-31
- 厂 商:
mozilla - 漏洞来源:
This vulnerability… -
漏洞简介
Mozilla Bugzilla 2.10至2.17版本的quips特征存在跨站脚本(XSS)漏洞。远程攻击者可以借助\”show all quips\”页面注入任意web脚本或HTML。
漏洞公告
Debian has released fixes which address this issue. It should be noted that this issue only affects those Debian users who have upgraded from version 2.10, which isn’t provided through Debian. Fixes are provided for Debian users who may have installed Bugzilla 2.10.
Patches are available for Bugzilla 2.14.4 and 2.16.1. Bugzilla 2.17 users are advised to obtain a patch via CVS. Detailed information is available in the referenced message.
Fixes are available:
Mozilla Bugzilla 2.10
-
Debian bugzilla-doc_2.14.2-0woody3_all.deb
http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla-doc_2
.14.2-0woody3_all.deb -
Debian bugzilla_2.14.2-0woody3_all.deb
http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla_2.14.
2-0woody3_all.deb
Mozilla Bugzilla 2.14
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.14.1
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.14.2
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.14.3
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.14.4
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.16
-
Bugzilla Bugzilla 2.16.2
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.16.1
-
Bugzilla Bugzilla 2.16.2
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.17
-
Bugzilla Bugzilla 2.17.3
http://www.bugzilla.org/download.html
参考网址
来源: XF
名称: bugzilla-quips-xss(10707)
链接:http://xforce.iss.net/xforce/xfdb/10707
来源: BID
名称: 6257
链接:http://www.securityfocus.com/bid/6257
来源: bugzilla.mozilla.org
链接:http://bugzilla.mozilla.org/show_bug.cgi?id=179329
来源: DEBIAN
名称: DSA-218
链接:http://www.debian.org/security/2002/dsa-218
来源: BUGTRAQ
名称: 20021126 XSS vulnerability in Bugzilla if upgraded from 2.10 or earlier
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=103837886416560&w=2