This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.
The remote FreeBSD host is missing one or more security-related
A Bugzilla Security Advisory reports : The following security issues
have been discovered in Bugzilla : Information Leak If the visibility
of a custom field is controlled by a product or a component of a
code generated for this custom field despite they should remain
Calling the User.get method with a 'groups' argument leaks the
existence of the groups depending on whether an error is thrown or
not. This method now also throws an error if the user calling this
method does not belong to these groups (independently of whether the
groups exist or not).
Trying to mark an attachment in a bug you cannot see as obsolete
discloses its description in the error message. The description of the
attachment is now removed from the error message. Cross-Site Scripting
Due to incorrectly filtered field values in tabular reports, it is
possible to inject code leading to XSS.
exploits to be created against domains that host this affected YUI
See also :
Update the affected packages.
Risk factor :
Medium / CVSS Base Score : 5.0
Family: FreeBSD Local Security Checks
Nessus Plugin ID: 62956 ()
Get Nessus Professional to scan unlimited IPs, run compliance checks & moreBuy Nessus Professional Now