CVE-2002-2260: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page.
Affected Software
28 affected components
Bugzilla=2.10
Bugzilla=2.12
Bugzilla=2.14
Bugzilla=2.14.1
Bugzilla=2.14.2
Bugzilla=2.14.3
Bugzilla=2.14.4
Bugzilla=2.14.5
Bugzilla=2.16
Bugzilla=2.16-rc1
Bugzilla=2.16.1
Bugzilla=2.16.2
Bugzilla=2.16.3
Bugzilla=2.16.4
Bugzilla=2.16.5
Bugzilla=2.16.6
Bugzilla=2.16.7
Bugzilla=2.16.8
Bugzilla=2.16.9
Bugzilla=2.16.10
Bugzilla=2.16.11
Bugzilla=2.17
Bugzilla=2.17.1
Bugzilla=2.17.3
Bugzilla=2.17.4
Bugzilla=2.17.5
Bugzilla=2.17.6
Bugzilla=2.17.7
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 18, 2007
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2260?
CVE-2002-2260 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2002-2260?
To fix CVE-2002-2260, upgrade Mozilla Bugzilla to version 2.18 or later, which includes the necessary patches.
3
What type of vulnerability is CVE-2002-2260?
CVE-2002-2260 is a Cross-Site Scripting (XSS) vulnerability allowing users to inject arbitrary web scripts.
4
Which versions of Mozilla Bugzilla are affected by CVE-2002-2260?
CVE-2002-2260 affects Mozilla Bugzilla versions from 2.10 to 2.17.
5
Can CVE-2002-2260 lead to data theft?
Yes, CVE-2002-2260 can potentially lead to data theft as it allows attackers to execute malicious scripts in the context of another user's session.