CVE-2013-0786
published 2013-02-24CVE-2013-0786: The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.66%
74.2th percentile
The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.
Affected
101 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | <= 3.6.12 | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0785 CVE-2013-0786 bugzilla: XSS and information leak flaws fixed in 3.6.13/4.0.10/4.2.5/4.4rc2
bugzilla·2013-02-21·CVSS 4.3
CVE-2013-0785 [MEDIUM] CVE-2013-0785 CVE-2013-0786 bugzilla: XSS and information leak flaws fixed in 3.6.13/4.0.10/4.2.5/4.4rc2
CVE-2013-0785 CVE-2013-0786 bugzilla: XSS and information leak flaws fixed in 3.6.13/4.0.10/4.2.5/4.4rc2
Two flaws were reported as fixed in upstream bugzilla [1]:
Vulnerability Details
Class: Cross-Site Scripting
Versions: 2.0 to 3.6.12, 3.7.1 to 4.0.9, 4.1.1 to 4.2.4,
4.3.1 to 4.4rc1
Fixed In: 3.6.13, 4.0.10, 4.2.5, 4.4rc2
Description: When viewing a single bug report, which is the default,
the bug ID is validated and rejected if it is invalid.
But when viewing several bug reports at once, which is
specified by the format=multiple parameter, invalid bug
IDs can go through and are sanitized in the HTML page
itself. But when an invalid page format is passed to the
CGI script, the wrong HTML page is called and data are not
correctly sanitized, which can lead to XSS.
References: https://b
Bugzilla
CVE-2013-0785 CVE-2013-0786 bugzilla: CSS and information leak flaws fixed in upstream 3.6.13/4.0.10/4.2.5/4.4rc2 [epel-all]
bugzilla·2013-02-21·CVSS 4.3
CVE-2013-0785 [MEDIUM] CVE-2013-0785 CVE-2013-0786 bugzilla: CSS and information leak flaws fixed in upstream 3.6.13/4.0.10/4.2.5/4.4rc2 [epel-all]
CVE-2013-0785 CVE-2013-0786 bugzilla: CSS and information leak flaws fixed in upstream 3.6.13/4.0.10/4.2.5/4.4rc2 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi note
http://www.bugzilla.org/security/3.6.12/http://www.mandriva.com/security/advisories?name=MDVSA-2013:066https://bugzilla.mozilla.org/show_bug.cgi?id=824399http://www.bugzilla.org/security/3.6.12/http://www.mandriva.com/security/advisories?name=MDVSA-2013:066https://bugzilla.mozilla.org/show_bug.cgi?id=824399
2013-02-24
Published