Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Bugzilla Multiple Vulnerabilities
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
Bugzilla is prone to multiple vulnerabilities.
Insight
Insight
Bugzilla is prone to multiple vulnerabilities: Cross-site scripting vulnerability in showdependencygraph.cgi when a local dot configuration is used, allows remote attackers to inject arbitrary web script or HTML via a crafted bug summary. (CVE-2015-8508) Template.pm does not properly construct CSV files, which allows remote attackers to obtain sensitive information by leveraging a web browser that interprets CSV data as JavaScript code. (CVE-2015-8509)
Affected Software
Affected Software
Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
Upgrade to Version 4.2.16, 4.4.11, 5.0.2 or later.