Описание
The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| html5lib | fixed | 0.999999999-1 | package | |
| html5lib | no-dsa | jessie | package | |
| html5lib | no-dsa | wheezy | package |
Примечания
Fixed by: https://github.com/html5lib/html5lib-python/commit/9b8d8eb5afbc066b7fac9390f5ec75e5e8a7cab7
https://www.sourceclear.com/registry/security/cross-site-scripting-xss-/python/sid-3068
https://www.openwall.com/lists/oss-security/2016/12/06/5
Связанные уязвимости
The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values.
The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values.
Improper Neutralization of Input During Web Page Generation in html5lib