Описание
samlr XML nodes comment attack
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.
Пакеты
Наименование
samlr
rubygems
Затронутые версииВерсия исправления
< 2.6.2
2.6.2
Связанные уязвимости
CVSS3: 7.5
nvd
больше 6 лет назад
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.