Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-5453
Description:Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using the H1, H2, and H3 HTML tags in global/header.html.tmpl, (2) description fields of certain items in various edit cgi scripts, and (3) the id parameter in showdependencygraph.cgi.
Test IDs: 1.3.6.1.4.1.25623.1.0.57578   1.3.6.1.4.1.25623.1.0.57581  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-5453
BugTraq ID: 20538
http://www.securityfocus.com/bid/20538
Bugtraq: 20061015 Security Advisory for Bugzilla 2.18.5, 2.20.2, 2.22, and 2.23.2 (Google Search)
http://www.securityfocus.com/archive/1/448777/100/100/threaded
Debian Security Information: DSA-1208 (Google Search)
http://www.debian.org/security/2006/dsa-1208
http://security.gentoo.org/glsa/glsa-200611-04.xml
http://www.osvdb.org/29544
http://www.osvdb.org/29545
http://www.osvdb.org/29549
http://securitytracker.com/id?1017063
http://secunia.com/advisories/22409
http://secunia.com/advisories/22790
http://secunia.com/advisories/22826
http://securityreason.com/securityalert/1760
http://www.vupen.com/english/advisories/2006/4035
XForce ISS Database: bugzilla-h1h2-tags-xss(29610)
https://exchange.xforce.ibmcloud.com/vulnerabilities/29610
XForce ISS Database: bugzilla-showdependencygraph(29619)
https://exchange.xforce.ibmcloud.com/vulnerabilities/29619




© 1998-2025 E-Soft Inc. All rights reserved.