internetnews.com: Bugzilla Bug Squashed | Linux Today

internetnews.com: Bugzilla Bug Squashed

Written By
Web Webster
Web Webster
Dec 31, 2002

“A potentially-dangerous security bug has been detected in
Bugzilla, a popular open-source bug-tracking software run by the
Mozilla Foundation.

“Researchers warned of the cross site scripting vulnerability
within Bugzilla that lets a remote attacker create a malicious link
containing script code which could be executed in the browser of a
legitimate user, in the context of the Web site running
Bugzilla.

“Because Bugzilla does not properly sanitize any input submitted
by users, malicious script could be embedded and may be exploited
to steal cookie-based authentication credentials from legitimate
users of the Web site running the vulnerable software…”

Complete
Story

Related Story:

Debian GNU/Linux Advisory: bugzilla
(Dec 30, 2002)

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.