Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4214

Опубликовано: 07 дек. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

2.3.5-1
hardy

ignored

end of life
intrepid

ignored

end of life, was needed
jaunty

ignored

end of life
karmic

ignored

end of life
lucid

not-affected

2.2.3-2
maverick

not-affected

2.3.5-1
natty

not-affected

2.3.5-1
upstream

released

2.3.5

Показывать по

Ссылки на источники

EPSS

Процентиль: 81%
0.01632
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 16 лет назад

Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.

nvd
около 16 лет назад

Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.

debian
около 16 лет назад

Cross-site scripting (XSS) vulnerability in the strip_tags function in ...

github
около 8 лет назад

Moderate severity vulnerability that affects rails

EPSS

Процентиль: 81%
0.01632
Низкий

4.3 Medium

CVSS2