Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bugzilla ErrorMessage 跨站脚本攻击漏洞
Vulnerability Description
Bugzilla是一套Web界面的Bug管理系统。 Bugzilla 2.18之前的版本,包括低于2.16.11的2.16.x版本,存在多个跨站点脚本攻击漏洞。 远程攻击者可以借助强制产生出错信息(比如使用action参数),注入任意的 HTML和web脚本。
CVSS Information
N/A
Vulnerability Type
N/A