Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-1330

Опубликовано: 26 апр. 2010
Источник: redhat
CVSS2: 5

Описание

The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=750306jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.

debian
больше 13 лет назад

The regular expression engine in JRuby before 1.4.1, when $KCODE is se ...

github
больше 4 лет назад

Cross-site Scripting in in JRuby

5 Medium

CVSS2