The application fails to sanitize the bug_id parameter in several pages such as edit_comment and edit_bug, leading to a cross site scripting vulnerability. CVE Link CVE-2010-3266 Exploit Type Exploits Cross Site Scripting (XSS) Known Vulnerabilities Product Name Impact