Описание
Plone Cross-site Scripting vulnerability in PortalTransforms
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.5 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2010-2422
- https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2010-19.yaml
- https://web.archive.org/web/20100728161728/http://secunia.com/advisories/40270
- https://web.archive.org/web/20200228223808/http://www.securityfocus.com/bid/40999
- http://plone.org/products/plone/security/advisories/cve-2010-unassigned-html-injection-in-safe_html
Пакеты
Plone
>= 2.1, <= 3.3.5
3.3.6
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone ...