CVE-2004-1061: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.
Affected Software
18 affected components
Bugzilla=2.16.8
Bugzilla=2.17.6
Bugzilla=2.16.1
Bugzilla=2.16.2
Bugzilla=2.16.11
Bugzilla=2.17.4
Bugzilla=2.17.1
Bugzilla=2.16.9
Bugzilla=2.16.7
Bugzilla=2.17.5
Bugzilla=2.17.3
Bugzilla=2.16.4
Bugzilla=2.16.3
Bugzilla=2.17.7
Bugzilla=2.17
Bugzilla=2.16.6
Bugzilla=2.16.5
Bugzilla=2.16.10
Event History
Dec 31, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1061?
CVE-2004-1061 is classified as a medium severity Cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2004-1061?
To fix CVE-2004-1061, users should upgrade Bugzilla to version 2.18 or higher.
3
Which versions of Bugzilla are affected by CVE-2004-1061?
CVE-2004-1061 affects Bugzilla versions prior to 2.18, including 2.16.x before 2.16.11.
4
What types of attacks does CVE-2004-1061 enable?
CVE-2004-1061 enables attackers to inject arbitrary HTML and web scripts through forced error messages.
5
Is CVE-2004-1061 being actively exploited?
While CVE-2004-1061 is an older vulnerability, it remains important to apply patches as outdated software may still be targeted.