Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-2480

Опубликовано: 23 июн. 2010
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=609573v0.3.4): Improper escaping of single quotes in escape.cgi (XSS)

EPSS

Процентиль: 49%
0.00257
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.

nvd
больше 15 лет назад

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.

debian
больше 15 лет назад

Mako before 0.3.4 relies on the cgi.escape function in the Python stan ...

CVSS3: 6.1
github
больше 3 лет назад

Mako contains Cross-site Scripting vulnerability

EPSS

Процентиль: 49%
0.00257
Низкий

5.8 Medium

CVSS2