CVE-2006-0916
Published Feb 28, 2006
Last updated 6 years ago
Overview
- Description
- Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.19.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F7CD64E-7FAA-40DC-B36E-8B7EB9D620FB" }, { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A749C7AB-6F60-469C-BD95-759205DDA345" }, { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B45F6C27-D89A-42A0-A304-5B0C57D2A9F1" }, { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "196B7CD8-D721-4CFB-B126-78758128E900" }, { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2053CFB4-602E-4141-BB3D-A440E2A31D85" }, { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.21.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31ACBA13-AC13-4469-862F-B3DD2327B6FC" }, { "criteria": "cpe:2.3:a:mozilla:bugzilla:2.21.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E9EC243-3E25-4234-A88A-FDD5B594BFBA" } ], "operator": "OR" } ] } ]