Back to search
CVE-2014-1573
Published: Oct 13, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.opennet.ru/opennews/art.shtml?num=40766
x_refsource_MISC
MDVSA-2014:200
vendor-advisory
x_refsource_MANDRIVA
70257
vdb-entry
x_refsource_BID
[oss-security] 20141007 "New Class of Vulnerability in Perl Web Applications"
mailing-list
x_refsource_MLIST
FEDORA-2014-12591
vendor-advisory
x_refsource_FEDORA
http://advisories.mageia.org/MGASA-2014-0412.html
x_refsource_CONFIRM
http://www.bugzilla.org/security/4.0.14/
x_refsource_CONFIRM
GLSA-201607-11
vendor-advisory
x_refsource_GENTOO
FEDORA-2014-12584
vendor-advisory
x_refsource_FEDORA
FEDORA-2014-12530
vendor-advisory
x_refsource_FEDORA
1030978
vdb-entry
x_refsource_SECTRACK
https://bugzilla.mozilla.org/show_bug.cgi?id=1075578
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now