CVE-2012-0466: XSS
template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins, which allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive bug information via a crafted web page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0466?
CVE-2012-0466 has been classified as a medium severity vulnerability.
How do I fix CVE-2012-0466?
To mitigate CVE-2012-0466, upgrade Bugzilla to version 3.6.9 or later.
What type of vulnerability is CVE-2012-0466?
CVE-2012-0466 is a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2012-0466?
Bugzilla versions 2.x and 3.x before 3.6.9, and various 4.x versions prior to 4.2.1 are affected by CVE-2012-0466.
What attack vectors are possible with CVE-2012-0466?
CVE-2012-0466 allows remote attackers to conduct cross-site scripting (XSS) attacks, which can potentially expose sensitive bug information.