CVE-2008-2103
published 2008-05-07CVE-2008-2103: Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.35%
68.6th percentile
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bugzilla: Cross-Site Scripting in the the "Format for Printing" view
vendor_redhat·2008-05-04·CVSS 4.3
CVE-2008-2103 [MEDIUM] CWE-79 bugzilla: Cross-Site Scripting in the the "Format for Printing" view
bugzilla: Cross-Site Scripting in the the "Format for Printing" view
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.
GHSA
GHSA-9gr5-vvqx-x7gh: Cross-site scripting (XSS) vulnerability in Bugzilla 2
ghsa_unreviewed·2022-05-01
CVE-2008-2103 [MEDIUM] CWE-79 GHSA-9gr5-vvqx-x7gh: Cross-site scripting (XSS) vulnerability in Bugzilla 2
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-2103 bugzilla: Cross-Site Scripting in the the "Format for Printing" view
bugzilla·2008-05-09·CVSS 4.3
CVE-2008-2103 [MEDIUM] CVE-2008-2103 bugzilla: Cross-Site Scripting in the the "Format for Printing" view
CVE-2008-2103 bugzilla: Cross-Site Scripting in the the "Format for Printing" view
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-2103 to the following vulnerability:
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.
Fixed upstream in: 3.0.4, 3.1.4, 2.22.4, and 2.20.6
Refences:
http://www.bugzilla.org/security/2.20.5/
https://bugzilla.mozilla.org/show_bug.cgi?id=425665
http://www.securityfocus.com/bid/29038
http://www.frsirt.com/english/advisories/2008/1428/references
http://www.securitytracker.com/id?1019967
http://secunia.com/advisories/30064
http://xforce.iss.net/xforce/xfdb/42216
Discussion:
Affe
Bugzilla
CVE-2008-0486 xine-lib / mplayer: array indexing vulnerability in FLAC parsing code
bugzilla·2008-02-05·CVSS 7.5
CVE-2008-0486 [HIGH] CVE-2008-0486 xine-lib / mplayer: array indexing vulnerability in FLAC parsing code
CVE-2008-0486 xine-lib / mplayer: array indexing vulnerability in FLAC parsing code
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-0486 to the following vulnerability:
Array index vulnerability in libmpdemux/demux_audio.c in MPlayer
1.0rc2 and SVN before r25917, and possibly earlier versions, as used
in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary
code via a crafted FLAC tag, which triggers a buffer overflow.
References:
http://www.securityfocus.com/archive/1/archive/1/487501/100/0/threaded
http://www.coresecurity.com/?action=item&id=2103
http://www.securityfocus.com/bid/27441
Discussion:
Patch in mplayer SVN:
http://svn.mplayerhq.hu/mplayer/trunk/libmpdemux/demux_audio.c?r1=25911&r2=25917
For xine-lib, affected code seems to live in open_
http://secunia.com/advisories/30064http://secunia.com/advisories/30167http://www.bugzilla.org/security/2.20.5/http://www.securityfocus.com/bid/29038http://www.securitytracker.com/id?1019967http://www.vupen.com/english/advisories/2008/1428/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=425665https://exchange.xforce.ibmcloud.com/vulnerabilities/42216https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00036.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00098.htmlhttp://secunia.com/advisories/30064http://secunia.com/advisories/30167http://www.bugzilla.org/security/2.20.5/http://www.securityfocus.com/bid/29038http://www.securitytracker.com/id?1019967http://www.vupen.com/english/advisories/2008/1428/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=425665https://exchange.xforce.ibmcloud.com/vulnerabilities/42216https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00036.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00098.html
2008-05-07
Published