Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.1:*:*:*:*:*:*:*", "matchCriteriaId": "19F19219-3AFD-4D8E-B02B-BFCBD1BC7C36", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.2:*:*:*:*:*:*:*", "matchCriteriaId": "B900D9A7-913A-4176-90CF-C7C3B09A4261", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.3:*:*:*:*:*:*:*", "matchCriteriaId": "B692910E-633D-4A88-B245-56A2B58DD4CB", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.4:*:*:*:*:*:*:*", "matchCriteriaId": "F86EE5DB-442B-4C78-8152-AF1048C6A974", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.5:*:*:*:*:*:*:*", "matchCriteriaId": "19B82A1A-56EB-41D5-8619-2A717E3A6ECF", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.6:*:*:*:*:*:*:*", "matchCriteriaId": "83A0406C-AAF2-4A4C-9567-E21DF1B6C46E", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.7:*:*:*:*:*:*:*", "matchCriteriaId": "64434BFC-DDC0-4C7D-B578-472B0610C89E", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.8:*:*:*:*:*:*:*", "matchCriteriaId": "A30F28D9-B000-4C26-A911-5E1B8A867BF6", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.9:*:*:*:*:*:*:*", "matchCriteriaId": "4A123F78-A671-4FB5-AE78-83762E9323C7", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.10:*:*:*:*:*:*:*", "matchCriteriaId": "28C34288-A326-4B71-99B0-DA9FFD28160F", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.11:*:*:*:*:*:*:*", "matchCriteriaId": "73648879-BB08-4BE4-A7FF-1E8DF4E264B4", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.17:*:*:*:*:*:*:*", "matchCriteriaId": "9B2FC5C7-B218-4B87-9805-F90AC0E7A281", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.1:*:*:*:*:*:*:*", "matchCriteriaId": "BBCDA64F-C49A-4F5B-B285-4079D8E3A499", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.3:*:*:*:*:*:*:*", "matchCriteriaId": "85ED3457-CC21-4DB3-931F-677F723E1B2A", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.4:*:*:*:*:*:*:*", "matchCriteriaId": "6C8711D3-55CF-4131-BBAC-6BE07068219F", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.5:*:*:*:*:*:*:*", "matchCriteriaId": "DF54FFA5-5177-46E6-9AFA-BA3345C16E8A", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.6:*:*:*:*:*:*:*", "matchCriteriaId": "69D7EA7C-B401-4F5A-AC08-2199DD117403", "vulnerable": true}, {"criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.7:*:*:*:*:*:*:*", "matchCriteriaId": "DC2DDC7C-CD2B-4597-A5E0-266A884958FC", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter."}], "id": "CVE-2004-1061", "lastModified": "2025-04-03T01:03:51.193", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}]}, "published": "2005-01-04T05:00:00.000", "references": [{"source": "cve@mitre.org", "url": "http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=001040"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://www.mikx.de/index.php?p=6"}, {"source": "cve@mitre.org", "url": "http://www.securityfocus.com/bid/12154"}, {"source": "cve@mitre.org", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=272620"}, {"source": "cve@mitre.org", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18728"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=001040"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://www.mikx.de/index.php?p=6"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/12154"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=272620"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18728"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "NVD-CWE-Other"}], "source": "nvd@nist.gov", "type": "Primary"}]}