CVE-2006-5453

Publication date 23 October 2006

Last updated 17 July 2025


Ubuntu priority

Description

Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using the H1, H2, and H3 HTML tags in global/header.html.tmpl, (2) description fields of certain items in various edit cgi scripts, and (3) the id parameter in showdependencygraph.cgi.

Status

Package Ubuntu Release Status
bugzilla 9.10 karmic
Fixed 2.22.1-2
9.04 jaunty
Fixed 2.22.1-2
8.10 intrepid
Fixed 2.22.1-2
8.04 LTS hardy
Fixed 2.22.1-2
7.10 gutsy
Fixed 2.22.1-2
7.04 feisty
Fixed 2.22.1-2
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities