Bugzilla におけるクロスサイトスクリプティングの脆弱性
| Title |
Bugzilla におけるクロスサイトスクリプティングの脆弱性
|
| Summary |
Bugzilla には、クロスサイトスクリプティングの脆弱性が存在します。
|
| Possible impacts |
第三者により、クロスサイトスクリプティング攻撃を実行される可能性があります。 |
| Solution |
ベンダ情報および参考情報を参照して適切な対策を実施してください。 |
| Publication Date |
May 16, 2006, midnight |
| Registration Date |
March 11, 2014, 5:43 p.m. |
| Last Update |
March 11, 2014, 5:43 p.m. |
|
CVSS2.0 : 警告
|
| Score |
4.3
|
| Vector |
AV:N/AC:M/Au:N/C:N/I:P/A:N |
Affected System
| Mozilla Foundation |
|
Bugzilla 2.20rc1 から 2.20
|
|
Bugzilla 2.21.1
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
| No |
Changed Details |
Date of change |
| 0 |
[2014年03月11日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
NVD Vulnerability Information
CVE-2006-2420
| Summary |
Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers. NOTE: this issue is not in Bugzilla itself, but rather due to design or documentation inconsistencies within RSS, or implementation vulnerabilities in RSS readers. While this issue normally would not be included in CVE, it is being identified since the Bugzilla developers have addressed it.
|
| Summary |
Update to version 2.18.5 or 2.20.1.
|
| Publication Date |
May 16, 2006, 7:02 p.m. |
| Registration Date |
Jan. 29, 2021, 3:37 p.m. |
| Last Update |
July 20, 2017, 10:31 a.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:mozilla:bugzilla:2.20:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:mozilla:bugzilla:2.21:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:mozilla:bugzilla:2.21.1:*:*:*:*:*:*:* |
|
|
|
|
Related information, measures and tools
Common Vulnerabilities List