CVE-2011-3657

Bugzilla <4.0.3 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when debug mode is used, allow remote attackers to inject arbitrary web script or HTML via vectors involving a (1) tabular report, (2) graphical report, or (3) new chart.

Scores

EPSS 0.0036
EPSS Percentile 57.7%

Classification

CWE
CWE-79
Status published

Affected Products (50)

mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
mozilla/bugzilla
... and 35 more

Timeline

Published Jan 02, 2012
Tracked Since Feb 18, 2026