CVE-2008-2103: XSS
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2103?
CVE-2008-2103 has been classified as a moderate severity vulnerability due to its nature of allowing cross-site scripting (XSS) attacks.
How do I fix CVE-2008-2103?
To remediate CVE-2008-2103, upgrade to a newer version of Bugzilla that addresses this XSS vulnerability.
Which versions of Bugzilla are affected by CVE-2008-2103?
CVE-2008-2103 affects Bugzilla versions 2.17.2 and later up to certain 3.x releases.
What type of attacks can be conducted through CVE-2008-2103?
CVE-2008-2103 can be exploited by attackers to inject arbitrary web scripts or HTML into the application, leading to XSS attacks.
Can CVE-2008-2103 be exploited remotely?
Yes, CVE-2008-2103 can be exploited remotely by attackers through the manipulated id parameter in Bugzilla.