Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00098.html
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00036.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/42216
https://bugzilla.mozilla.org/show_bug.cgi?id=425665
http://www.vupen.com/english/advisories/2008/1428/references
http://www.securitytracker.com/id?1019967
http://www.bugzilla.org/security/2.20.5/