4.3
CVSSv2

CVE-2006-2420

Published: 16/05/2006 Updated: 20/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Bugzilla 2.20rc1 up to and including 2.20 and 2.21.1, when using RSS 1.0, allows remote malicious users to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers. NOTE: this issue is not in Bugzilla itself, but rather due to design or documentation inconsistencies within RSS, or implementation vulnerabilities in RSS readers. While this issue normally would not be included in CVE, it is being identified since the Bugzilla developers have addressed it.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 2.20

mozilla bugzilla 2.21

mozilla bugzilla 2.21.1