Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-97wc-2m3g-wmcq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html.

Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html.

EPSS

Процентиль: 95%
0.16214
Средний

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 15 лет назад

Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html.

nvd
больше 15 лет назад

Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html.

debian
больше 15 лет назад

Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js ...

EPSS

Процентиль: 95%
0.16214
Средний

Дефекты

CWE-79