---
title: "CVE-2004-0705\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2004-0705?format=md
keywords: index, follow
---

# CVE-2004-0705

Publication date 27 July 2004

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple cross-site scripting (XSS) vulnerabilities in (1)
editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4)
editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla
2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to
execute arbitrary JavaScript as other users via a URL parameter.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| bugzilla | 7.04 feisty | Fixed 2.20-1 |
| 6.10 edgy | Fixed 2.20-1 |
| 6.06 LTS dapper | Fixed 2.20-1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0705)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2004-0705)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2004-0705)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2004-0705)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2004-0705>
