Lucene search

K
nvd[email protected]NVD:CVE-2013-1743
HistoryOct 24, 2013 - 10:53 a.m.

CVE-2013-1743

2013-10-2410:53:09
CWE-79
web.nvd.nist.gov
7

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

57.9%

Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as demonstrated by the (1) summary or (2) real name field. NOTE: this issue exists because of an incomplete fix for CVE-2012-4189.

Affected configurations

Nvd
Node
mozillabugzillaMatch4.1
OR
mozillabugzillaMatch4.1.1
OR
mozillabugzillaMatch4.1.2
OR
mozillabugzillaMatch4.1.3
Node
mozillabugzillaMatch4.3
OR
mozillabugzillaMatch4.3.1
OR
mozillabugzillaMatch4.3.2
OR
mozillabugzillaMatch4.3.3
Node
mozillabugzillaMatch4.2
OR
mozillabugzillaMatch4.2rc1
OR
mozillabugzillaMatch4.2rc2
OR
mozillabugzillaMatch4.2.1
OR
mozillabugzillaMatch4.2.2
OR
mozillabugzillaMatch4.2.3
OR
mozillabugzillaMatch4.2.4
OR
mozillabugzillaMatch4.2.5
Node
mozillabugzillaMatch4.4
OR
mozillabugzillaMatch4.4rc1
OR
mozillabugzillaMatch4.4rc2
VendorProductVersionCPE
mozillabugzilla4.1cpe:2.3:a:mozilla:bugzilla:4.1:*:*:*:*:*:*:*
mozillabugzilla4.1.1cpe:2.3:a:mozilla:bugzilla:4.1.1:*:*:*:*:*:*:*
mozillabugzilla4.1.2cpe:2.3:a:mozilla:bugzilla:4.1.2:*:*:*:*:*:*:*
mozillabugzilla4.1.3cpe:2.3:a:mozilla:bugzilla:4.1.3:*:*:*:*:*:*:*
mozillabugzilla4.3cpe:2.3:a:mozilla:bugzilla:4.3:*:*:*:*:*:*:*
mozillabugzilla4.3.1cpe:2.3:a:mozilla:bugzilla:4.3.1:*:*:*:*:*:*:*
mozillabugzilla4.3.2cpe:2.3:a:mozilla:bugzilla:4.3.2:*:*:*:*:*:*:*
mozillabugzilla4.3.3cpe:2.3:a:mozilla:bugzilla:4.3.3:*:*:*:*:*:*:*
mozillabugzilla4.2cpe:2.3:a:mozilla:bugzilla:4.2:*:*:*:*:*:*:*
mozillabugzilla4.2cpe:2.3:a:mozilla:bugzilla:4.2:rc1:*:*:*:*:*:*
Rows per page:
1-10 of 191

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

57.9%