Candidate: CVE-2009-0481 PublicDate: 2009-02-09 17:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0481 Description: Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_bugzilla: upstream_bugzilla: released (3.2.1) dapper_bugzilla: ignored (reached end-of-life) gutsy_bugzilla: needed (reached end-of-life) hardy_bugzilla: ignored (reached end-of-life) intrepid_bugzilla: needed (reached end-of-life) jaunty_bugzilla: ignored (reached end-of-life) karmic_bugzilla: not-affected (3.2.4.0-3) lucid_bugzilla: not-affected (3.2.4.0-3) maverick_bugzilla: not-affected (3.2.4.0-3) natty_bugzilla: not-affected (3.2.4.0-3) oneiric_bugzilla: not-affected (3.2.4.0-3) devel_bugzilla: not-affected (3.2.4.0-3)