Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-5453 | First vendor Publication | 2006-10-23 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:S/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 3.5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 6.8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using the H1, H2, and H3 HTML tags in global/header.html.tmpl, (2) description fields of certain items in various edit cgi scripts, and (3) the id parameter in showdependencygraph.cgi. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5453 |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200611-04 (bugzilla) File : nvt/glsa_200611_04.nasl |
2008-09-04 | Name : FreeBSD Ports: bugzilla, ja-bugzilla File : nvt/freebsd_bugzilla2.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1208-1 (bugzilla) File : nvt/deb_1208_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
29545 | Bugzilla Multiple Description Field XSS Bugzilla contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate various description field variables upon submission. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-11-20 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1208.nasl - Type : ACT_GATHER_INFO |
2006-11-20 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_6d68618a719911dba2ad000c6ec775d9.nasl - Type : ACT_GATHER_INFO |
2006-11-20 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200611-04.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:19:12 |
|
2024-11-28 12:10:21 |
|
2021-05-04 12:04:45 |
|
2021-04-22 01:05:22 |
|
2020-05-23 00:18:35 |
|
2018-10-18 00:19:45 |
|
2017-07-20 09:23:58 |
|
2016-06-28 15:59:12 |
|
2016-04-26 15:12:49 |
|
2014-02-17 10:37:39 |
|
2013-05-11 11:12:13 |
|