Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3146

Опубликовано: 15 апр. 2014
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5python-lxmlWill not fix
Red Hat Enterprise Linux 6python-lxmlWill not fix
Red Hat Enterprise Linux 7python-lxmlWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1092613python-lxml: clean_html input sanitization flaw

EPSS

Процентиль: 89%
0.04268
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 12 лет назад

Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.

CVSS3: 6.1
nvd
почти 12 лет назад

Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.

CVSS3: 6.1
debian
почти 12 лет назад

Incomplete blacklist vulnerability in the lxml.html.clean module in lx ...

CVSS3: 6.1
github
почти 4 года назад

lxml Cross-site Scripting Via Control Characters

fstec
почти 12 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить целостность защищаемой информации

EPSS

Процентиль: 89%
0.04268
Низкий

2.6 Low

CVSS2