VYPR
Unrated severityNVD Advisory· Published Feb 28, 2006· Updated Jun 16, 2026

CVE-2006-0916

CVE-2006-0916

Description

Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • cpe:2.3:a:mozilla:bugzilla:2.19.3:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:mozilla:bugzilla:2.19.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:2.20:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:2.21.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:2.21.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:2.21:*:*:*:*:*:*:*
    • (no CPE)range: >=2.19.3, <=2.20

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.