Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w37c-q653-qg95

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

actionpack Cross-site Scripting vulnerability

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

Пакеты

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.2

4.0.2

EPSS

Процентиль: 79%
0.01963
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

redhat
больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

nvd
больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

debian
больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the simple_format helper i ...

EPSS

Процентиль: 79%
0.01963
Низкий

Дефекты

CWE-79