Total vulnerabilities in the database
Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.
Software | From | Fixed in |
---|---|---|
mozilla / bugzilla | 2.19.3 | 2.19.3.x |
mozilla / bugzilla | 2.20-rc2 | 2.20-rc2.x |
mozilla / bugzilla | 2.20-rc1 | 2.20-rc1.x |
mozilla / bugzilla | 2.20 | 2.20.x |
mozilla / bugzilla | 2.21.2 | 2.21.2.x |
mozilla / bugzilla | 2.21.1 | 2.21.1.x |
mozilla / bugzilla | 2.21 | 2.21.x |