CVE-2003-0602
Bugzilla 2.16.x < 2.16.3 and 2.17.x < 2.17.4 - Cross-Site Scripting via HTML Templates and GraphViz Attributes
Title source: llmDescription
Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.
References (4)
Core 4
Core References
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/6861
Vendor Advisory vendor-advisory
x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000653
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/6868
Issue Tracking x_refsource_confirm
http://www.bugzilla.org/security/2.16.2/
Scores
EPSS
0.0115
EPSS Percentile
63.4%
Details
Status
published
Products (6)
mozilla/bugzilla
2.16
mozilla/bugzilla
2.16.1
mozilla/bugzilla
2.16.2
mozilla/bugzilla
2.17
mozilla/bugzilla
2.17.1
mozilla/bugzilla
2.17.3
Published
Aug 27, 2003
Tracked Since
Feb 18, 2026