CVE-2006-0916

Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:bugzilla:2.19.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.21:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.21.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bugzilla:2.21.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:07

Type Values Removed Values Added
References () http://secunia.com/advisories/18979 - Vendor Advisory () http://secunia.com/advisories/18979 - Vendor Advisory
References () http://securityreason.com/securityalert/464 - () http://securityreason.com/securityalert/464 -
References () http://www.securityfocus.com/archive/1/425584/100/0/threaded - () http://www.securityfocus.com/archive/1/425584/100/0/threaded -
References () http://www.securityfocus.com/bid/16745 - Vendor Advisory () http://www.securityfocus.com/bid/16745 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2006/0692 - () http://www.vupen.com/english/advisories/2006/0692 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=325079 - Patch, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=325079 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/24821 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/24821 -

Information

Published : 2006-02-28 11:02

Updated : 2024-11-21 00:07


NVD link : CVE-2006-0916

Mitre link : CVE-2006-0916

CVE.ORG link : CVE-2006-0916


JSON object : View

Products Affected

mozilla

  • bugzilla