CVE-2013-0785: XSS
Cross-site scripting (XSS) vulnerability in showbug.cgi in Bugzilla before 3.6.13, 3.7.x and 4.0.x before 4.0.10, 4.1.x and 4.2.x before 4.2.5, and 4.3.x and 4.4.x before 4.4rc2 allows remote attackers to inject arbitrary web script or HTML via the id parameter in conjunction with an invalid value of the format parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0785?
CVE-2013-0785 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2013-0785?
To fix CVE-2013-0785, upgrade Bugzilla to version 3.6.13, 4.0.10, 4.2.5, or later.
What versions of Bugzilla are affected by CVE-2013-0785?
CVE-2013-0785 affects Bugzilla versions prior to 3.6.13, 4.0.10, 4.2.5, and several 4.x versions listed in the advisory.
Can CVE-2013-0785 be exploited remotely?
Yes, CVE-2013-0785 can be exploited remotely by attackers to inject malicious scripts through the ID parameter.
Is CVE-2013-0785 related to any other vulnerabilities?
CVE-2013-0785 is a standalone XSS vulnerability but may have implications in conjunction with other vulnerabilities affecting web applications.