CVE-2004-0705: XSS
Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0705?
CVE-2004-0705 has a high severity due to its ability to allow remote attackers to execute arbitrary JavaScript code through multiple cross-site scripting vulnerabilities in Bugzilla.
How do I fix CVE-2004-0705?
To fix CVE-2004-0705, update Bugzilla to versions 2.16.6 or later and 2.18rc1 or later, which address the vulnerabilities.
What versions of Bugzilla are affected by CVE-2004-0705?
CVE-2004-0705 affects Bugzilla versions 2.16.x prior to 2.16.6 and 2.18 prior to 2.18rc1.
What are the consequences of CVE-2004-0705 exploitation?
The exploitation of CVE-2004-0705 can lead to unauthorized access to user data and potential hijacking of user sessions.
Is CVE-2004-0705 a persistent vulnerability in Bugzilla?
CVE-2004-0705 is not persistent as it is tied to specific versions of Bugzilla, which have since been patched.