Description
|
|
Multiple vulnerabilities have been identified in Bugzilla, which could be exploited by attackers to gain knowledge of sensitive information.
The first issue is caused by an input validation error when processing user-supplied URLs, which could allow attackers to inject headers and content in a user's browser.
The second issue is caused by an error in the Old Charts system that generates graphs in the "graphs/" directory with predictable names, which could allow attackers to view product names and charted information.
The third vulnerability is caused by an input validation error in YUI, which could allow cross site scripting attacks.
|