First published: Mon Aug 27 2007(Updated: )
Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the buildid field in the "guided form."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =3.0.0 | |
Mozilla Bugzilla | =2.17.6 | |
Mozilla Bugzilla | =2.18.5 | |
Mozilla Bugzilla | =2.19.3 | |
Mozilla Bugzilla | =2.20-rc2 | |
Mozilla Bugzilla | =2.20-rc1 | |
Mozilla Bugzilla | =2.20 | |
Mozilla Bugzilla | =2.19 | |
Mozilla Bugzilla | =2.18-rc1 | |
Mozilla Bugzilla | =2.17.4 | |
Mozilla Bugzilla | =2.17.1 | |
Mozilla Bugzilla | =2.22.1 | |
Mozilla Bugzilla | =2.20.1 | |
Mozilla Bugzilla | =2.22.2 | |
Mozilla Bugzilla | =2.18.1 | |
Mozilla Bugzilla | =2.22-rc1 | |
Mozilla Bugzilla | =2.19.1 | |
Mozilla Bugzilla | =2.17.5 | |
Mozilla Bugzilla | =2.22 | |
Mozilla Bugzilla | =2.17.3 | |
Mozilla Bugzilla | =2.20.3 | |
Mozilla Bugzilla | =2.18.4 | |
Mozilla Bugzilla | =2.18 | |
Mozilla Bugzilla | =2.18.3 | |
Mozilla Bugzilla | =2.17.7 | |
Mozilla Bugzilla | =2.20.2 | |
Mozilla Bugzilla | =2.18-rc3 | |
Mozilla Bugzilla | =2.18.2 | |
Mozilla Bugzilla | =2.18-rc2 | |
Mozilla Bugzilla | =2.19.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4543 is considered a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2007-4543, upgrade Bugzilla to version 2.22.3 or later, or 3.0.1 or later.
CVE-2007-4543 affects Bugzilla versions from 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1.
CVE-2007-4543 is a cross-site scripting (XSS) vulnerability allowing remote code injection.
Yes, CVE-2007-4543 can be exploited remotely by injecting malicious scripts through the buildid field in the guided form.