Bugzilla XSS / Insecure Temporary File Names

medium Nessus Network Monitor Plugin ID 1555

Synopsis

The remote server is running Bugzilla, a bug tracking system.

Description

The remote server is running Bugzilla, a bug tracking system. There is a flaw in the remote installation of Bugzilla that makes it vulnerable to cross-site scripting attacks and that may allow local attackers to escalate their privileges due to the use of insecure temporary file names.

Solution

Upgrade to Bugzilla 2.16.3, 2.17.4 or higher.

See Also

http://www.bugzilla.org

Plugin Details

Severity: Medium

ID: 1555

Family: CGI

Published: 8/18/2004

Updated: 6/1/2015

Nessus ID: 11462