This allows remote attackers to inject arbitrary web script or HTML via a crafted patch, related to content sniffing.
Credit:
The information has been provided by Frederic Buclin, Byron Jones, Max Kanat-Alexander, Reed Loden, Neal Poole, Neil Rashbrook, David Lawrence.
The original article can be found at: http://www.securityfocus.com/bid/49042/info
Vulnerable Systems:
* Bugzilla 2.4 through 2.22.7
* Bugzilla 3.0.x through 3.3.x
* Bugzilla 3.4.x before 3.4.12
* Bugzilla 3.5.x
* Bugzilla 3.6.x before 3.6.6
* Bugzilla 3.7.x
* Bugzilla 4.0.x before 4.0.2
* Bugzilla 4.1.x before 4.1.3
Successfully exploiting these issues may allow an attacker to bypass certain security restrictions, obtain sensitive information, execute arbitrary script code in the browser of an unsuspecting user, steal cookie-based authentication credentials, and perform actions in the vulnerable application in the context of the victim.
Vendor Status:
Bugzilla has issued an update to correct this vulnerability