CVE-2003-0602

Bugzilla 2.16.x < 2.16.3 and 2.17.x < 2.17.4 - Cross-Site Scripting via HTML Templates and GraphViz Attributes

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.

References (4)

Core 4
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6861
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000653
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6868
Issue Tracking x_refsource_confirm
http://www.bugzilla.org/security/2.16.2/

Scores

EPSS 0.0115
EPSS Percentile 63.4%

Details

Status published
Products (6)
mozilla/bugzilla 2.16
mozilla/bugzilla 2.16.1
mozilla/bugzilla 2.16.2
mozilla/bugzilla 2.17
mozilla/bugzilla 2.17.1
mozilla/bugzilla 2.17.3
Published Aug 27, 2003
Tracked Since Feb 18, 2026