CVE Vulnerabilities

CVE-2003-0602

Published: Aug 27, 2003 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.

Affected Software

Name Vendor Start Version End Version
Bugzilla Mozilla 2.16 2.16
Bugzilla Mozilla 2.16.1 2.16.1
Bugzilla Mozilla 2.16.2 2.16.2
Bugzilla Mozilla 2.17 2.17
Bugzilla Mozilla 2.17.1 2.17.1
Bugzilla Mozilla 2.17.3 2.17.3

References