CVE-2011-2976Cross-site Scripting in Mozilla Bugzilla

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 36.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 9
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, and 3.4.x before 3.4.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving a BUGLIST cookie.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla95 versions+94

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h9cm-vvrp-mf5x: Cross-site scripting (XSS) vulnerability in Bugzilla 22022-05-17
CVEList
CVE-2011-2976: Cross-site scripting (XSS) vulnerability in Bugzilla 22011-08-09

💬Community

2
Bugzilla
CVE-2011-2976 CVE-2011-2379 CVE-2011-2380 CVE-2011-2979 CVE-2011-2381 CVE-2011-2978 CVE-2011-2977 bugzilla: multiple security flaws fixed in 3.4.12, 3.6.6, 4.0.2, and 4.1.3 [epel-all]2011-08-08
Bugzilla
CVE-2011-2976 CVE-2011-2379 CVE-2011-2380 CVE-2011-2979 CVE-2011-2381 CVE-2011-2978 CVE-2011-2977 bugzilla: multiple security flaws fixed in 3.4.12, 3.6.6, 4.0.2, and 4.1.32011-08-08
CVE-2011-2976 — Cross-site Scripting in Mozilla | cvebase