Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-2480

Опубликовано: 02 июл. 2010
Источник: debian
EPSS Низкий

Описание

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
makofixed0.3.4-1package
makono-dsalennypackage

EPSS

Процентиль: 49%
0.00257
Низкий

Связанные уязвимости

ubuntu
больше 15 лет назад

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.

redhat
больше 15 лет назад

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.

nvd
больше 15 лет назад

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.

CVSS3: 6.1
github
больше 3 лет назад

Mako contains Cross-site Scripting vulnerability

EPSS

Процентиль: 49%
0.00257
Низкий