Bugzilla Cross Site Scripting Vulnerabilities(CVE-2011-3657)
14 Mar. 2012
Summary
Bugzilla is prone to a cross-site request-forgery vulnerability.
Credit:
The information has been provided by Byron Jones, Frederic Buclin, Gervase Markham, David Lawrence, RedTeam Pentesting, Reed Loden, Max Kanat-Alexander, Mario Gomes.
The original article can be found at: http://www.securityfocus.com/bid/51213
Vulnerable Systems:
* Red Hat Fedora 16
* Red Hat Fedora 15
* Mozilla Bugzilla 4.1.3 and prior
Immune Systems:
* Mozilla Bugzilla 4.0.3
* Mozilla Bugzilla 3.6.7
* Mozilla Bugzilla 3.4.13
* Mozilla Bugzilla 4.2rc1
Tabular and graphical reports, as well as new charts have a debug mode which displays raw data as plain text. This text is not correctly escaped and a crafted URL could use this vulnerability to inject code leading to XSS
Vendor Status:
Bugzilla has issued an update to correct this vulnerability