Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-6416

Опубликовано: 03 дек. 2013
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

Отчет

Not vulnerable. This issue did not affect the versions of rubygem-actionpack as shipped with various Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ruby193-rubygem-actionpackNot affected
OpenShift Enterprise 1ruby193-rubygem-actionpackNot affected
Red Hat OpenStack Platform 3ruby193-rubygem-actionpackNot affected
Red Hat OpenStack Platform 4ruby193-rubygem-actionpackNot affected
Red Hat Satellite 6ruby193-rubygem-actionpackNot affected
Red Hat Software Collectionsror40-rubygem-actionpackNot affected
Red Hat Software Collectionsruby193-rubygem-actionpackNot affected
Red Hat Subscription Asset Managerruby193-rubygem-actionpackNot affected
Red Hat Subscription Asset Managerrubygem-actionpackNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1036914rubygem-actionpack: simple_format XSS

EPSS

Процентиль: 46%
0.00236
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

nvd
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

debian
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the simple_format helper i ...

github
больше 8 лет назад

actionpack Cross-site Scripting vulnerability

EPSS

Процентиль: 46%
0.00236
Низкий

4.3 Medium

CVSS2