Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10516

Опубликовано: 23 окт. 2017
Источник: debian

Описание

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-werkzeugfixed0.11.11+dfsg1-1package
python-werkzeugfixed0.9.6+dfsg-1+deb8u1jessiepackage

Примечания

  • http://blog.neargle.com/2016/09/21/flask-src-review-get-a-xss-from-debuger/

  • https://github.com/pallets/werkzeug/pull/1001

  • https://github.com/pallets/werkzeug/commit/1034edc7f901dd645ec6e462754111b39002bd65

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

CVSS3: 7.1
redhat
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

CVSS3: 6.1
nvd
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

CVSS3: 6.1
github
больше 3 лет назад

Pallets Werkzeug cross-site scripting vulnerability