CVE-2007-0791: XSS
Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0791?
CVE-2007-0791 has a moderate severity due to its potential to allow remote attackers to inject malicious web scripts.
How do I fix CVE-2007-0791?
To mitigate CVE-2007-0791, upgrade Bugzilla to versions 2.23.4 or later, where the XSS vulnerability has been addressed.
What versions of Bugzilla are affected by CVE-2007-0791?
CVE-2007-0791 affects Bugzilla versions 2.20.1 to 2.23.3, including earlier versions down to 2.20.1.
What type of vulnerability is CVE-2007-0791?
CVE-2007-0791 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2007-0791 be exploited without user interaction?
Yes, CVE-2007-0791 can be exploited by attackers without requiring user interaction through specially crafted Atom feeds.