Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4459

Опубликовано: 30 дек. 2009
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

released

0.9.0

Показывать по

Ссылки на источники

EPSS

Процентиль: 51%
0.00276
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 16 лет назад

Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.

debian
почти 16 лет назад

Redmine 0.8.7 and earlier uses the title tag before defining the chara ...

github
больше 3 лет назад

Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary script via UTF-7 encoded values in the title parameter to a new issue page, which may be interpreted as script by Internet Explorer 7 and 8.

EPSS

Процентиль: 51%
0.00276
Низкий

4.3 Medium

CVSS2