CVE-2006-0916: High severity Bugzilla vulnerability
Published Feb 28, 2006
·Updated
Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.
Affected Software
7 affected components
Bugzilla=2.19.3
Bugzilla=2.20-rc2
Bugzilla=2.20-rc1
Bugzilla=2.20
Bugzilla=2.21.2
Bugzilla=2.21.1
Bugzilla=2.21
Remediation
Patch Available
Event History
Feb 28, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0916?
CVE-2006-0916 has been rated as a moderate severity vulnerability.
2
How do I fix CVE-2006-0916?
To fix CVE-2006-0916, upgrade Bugzilla to version 2.21 or later.
3
Who is affected by CVE-2006-0916?
CVE-2006-0916 affects users of Bugzilla versions 2.19.3 through 2.21.2.
4
What type of vulnerability is CVE-2006-0916?
CVE-2006-0916 is a URL redirection vulnerability that can lead to information exposure.
5
What impact can CVE-2006-0916 have on users?
CVE-2006-0916 can potentially allow malicious websites to capture form data submitted by users.