CVE-2004-1061
Bugzilla < 2.18 - Cross-Site Scripting via Forced Error Messages
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.
References (6)
Core 6
Core References
Vendor Advisory vendor-advisory
x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=001040
Vendor Advisory x_refsource_misc
http://www.mikx.de/index.php?p=6
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/12154
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18728
Vendor Advisory mailing-list
x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=272620
Scores
EPSS
0.0103
EPSS Percentile
60.1%
Details
Status
published
Products (18)
mozilla/bugzilla
2.16.1
mozilla/bugzilla
2.16.2
mozilla/bugzilla
2.16.3
mozilla/bugzilla
2.16.4
mozilla/bugzilla
2.16.5
mozilla/bugzilla
2.16.6
mozilla/bugzilla
2.16.7
mozilla/bugzilla
2.16.8
mozilla/bugzilla
2.16.9
mozilla/bugzilla
2.16.10
... and 8 more
Published
Jan 04, 2005
Tracked Since
Feb 18, 2026