CVE-2011-2379

medium

Description

Cross-site scripting (XSS) vulnerability in Bugzilla 2.4 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3, when Internet Explorer before 9 or Safari before 5.0.6 is used for Raw Unified mode, allows remote attackers to inject arbitrary web script or HTML via a crafted patch, related to content sniffing.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/69033

http://www.securityfocus.com/bid/49042

http://www.osvdb.org/74297

http://www.debian.org/security/2011/dsa-2322

http://www.bugzilla.org/security/3.4.11/

http://secunia.com/advisories/45501

Details

Source: Mitre, NVD

Published: 2011-08-09

Updated: 2021-07-23

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium