Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Bugzilla Internal Error Cross-Site Scripting Vulnerability

Bugzilla is prone to a cross-site scripting vulnerability. The issue is exposed when the software renders internal errors that include user-supplied input.

An attacker may exploit this issue by enticing a user to follow a link that will cause hostile HTML and script code to be rendered in an internal error page. Exploitation may allow an attacker to steal cookie-based authentication credentials or to mount other attacks.







 

Privacy Statement
Copyright 2008, SecurityFocus