FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-5453

This CVE name corresponds to:

Entered Topic
2006-11-11 bugzilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-5453
Phase Assigned(20061023)

Description

Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using the H1, H2, and H3 HTML tags in global/header.html.tmpl, (2) description fields of certain items in various edit cgi scripts, and (3) the id parameter in showdependencygraph.cgi.

References

Source Reference
BUGTRAQ 20061015 Security Advisory for Bugzilla 2.18.5, 2.20.2, 2.22, and 2.23.2
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=206037
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=330555
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=355728
CONFIRM http://www.bugzilla.org/security/2.18.5/
DEBIAN DSA-1208
GENTOO GLSA-200611-04
BID 20538
VUPEN ADV-2006-4035
OSVDB 29545
OSVDB 29544
OSVDB 29549
SECTRACK 1017063
SECUNIA 22790
SECUNIA 22826
SECUNIA 22409
SREASON 1760
XF bugzilla-h1h2-tags-xss(29610)
XF bugzilla-showdependencygraph(29619)