CVE Vulnerabilities

CVE-2006-0916

Published: Feb 28, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Bugzilla 2.19.3 through 2.20 does not properly handle // sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the users browser to send the form data to another domain.

Affected Software

Name Vendor Start Version End Version
Bugzilla Mozilla 2.19.3 2.19.3
Bugzilla Mozilla 2.20 2.20
Bugzilla Mozilla 2.20 2.20
Bugzilla Mozilla 2.20 2.20
Bugzilla Mozilla 2.21.2 2.21.2
Bugzilla Mozilla 2.21.1 2.21.1
Bugzilla Mozilla 2.21 2.21

References