CVE-2003-0602
N/A
N/A
Summary
Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/bid/6861
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000653
- http://www.securityfocus.com/bid/6868
- http://www.bugzilla.org/security/2.16.2/
References
- http://www.securityfocus.com/bid/6861
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000653
- http://www.securityfocus.com/bid/6868
- http://www.bugzilla.org/security/2.16.2/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.