First published: Tue Jul 29 2003(Updated: )
Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.17.1 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.17.3 | |
Mozilla Bugzilla | =2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0602 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2003-0602, upgrade Bugzilla to version 2.16.3 or 2.17.4 or later, which address this vulnerability.
CVE-2003-0602 affects Bugzilla versions 2.16.x before 2.16.3 and 2.17.x before 2.17.4.
CVE-2003-0602 can enable remote attackers to perform cross-site scripting (XSS) attacks via arbitrary HTML or web script.
Symptomatic exploitation of CVE-2003-0602 may include unexpected web page behavior, data theft, or unauthorized actions taken on behalf of users.