CVE

Id
9489  
CVE No.
CVE-2004-1061  
Status
Candidate  
Description
Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.  
Phase
Assigned (20041123)  
Votes
None (candidate not yet proposed)  
Comments