CVE-2011-2976: XSS
Cross-site scripting (XSS) vulnerability in Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, and 3.4.x before 3.4.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving a BUGLIST cookie.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2976?
CVE-2011-2976 has a medium severity rating due to its potential for creating cross-site scripting vulnerabilities.
How do I fix CVE-2011-2976?
To fix CVE-2011-2976, update Bugzilla to version 3.4.12 or later, which addresses this vulnerability.
What versions of Bugzilla are affected by CVE-2011-2976?
CVE-2011-2976 affects Bugzilla versions from 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, and before 3.4.12.
What type of vulnerability is CVE-2011-2976?
CVE-2011-2976 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Can CVE-2011-2976 be exploited remotely?
Yes, CVE-2011-2976 can be exploited remotely, allowing attackers to execute malicious scripts in the context of the victim's browser.