First published: Wed Jul 21 2004(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.17.6 | |
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.17.4 | |
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.17.1 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.4 | |
Mozilla Bugzilla | =2.6 | |
Mozilla Bugzilla | =2.17.5 | |
Mozilla Bugzilla | =2.17.3 | |
Mozilla Bugzilla | =2.4 | |
Mozilla Bugzilla | =2.16.4 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.8 | |
Mozilla Bugzilla | =2.16.3 | |
Mozilla Bugzilla | =2.14.5 | |
Mozilla Bugzilla | =2.17.7 | |
Mozilla Bugzilla | =2.17 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.16.5 | |
Mozilla Bugzilla | =2.14 | |
Mozilla Bugzilla | =2.4 | |
Mozilla Bugzilla | =2.6 | |
Mozilla Bugzilla | =2.8 | |
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.14 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.4 | |
Mozilla Bugzilla | =2.14.5 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.16.3 | |
Mozilla Bugzilla | =2.16.4 | |
Mozilla Bugzilla | =2.16.5 | |
Mozilla Bugzilla | =2.17 | |
Mozilla Bugzilla | =2.17.1 | |
Mozilla Bugzilla | =2.17.3 | |
Mozilla Bugzilla | =2.17.4 | |
Mozilla Bugzilla | =2.17.5 | |
Mozilla Bugzilla | =2.17.6 | |
Mozilla Bugzilla | =2.17.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0705 has a high severity due to its ability to allow remote attackers to execute arbitrary JavaScript code through multiple cross-site scripting vulnerabilities in Bugzilla.
To fix CVE-2004-0705, update Bugzilla to versions 2.16.6 or later and 2.18rc1 or later, which address the vulnerabilities.
CVE-2004-0705 affects Bugzilla versions 2.16.x prior to 2.16.6 and 2.18 prior to 2.18rc1.
The exploitation of CVE-2004-0705 can lead to unauthorized access to user data and potential hijacking of user sessions.
CVE-2004-0705 is not persistent as it is tied to specific versions of Bugzilla, which have since been patched.