Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4924

Опубликовано: 02 июл. 2010
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

1.0.5-4build1
esm-infra-legacy/trusty

not-affected

1.0.5-4build1
hardy

ignored

end of life
jaunty

ignored

end of life
karmic

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

ignored

end of life
oneiric

ignored

end of life

Показывать по

Ссылки на источники

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 15 лет назад

Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.

debian
больше 15 лет назад

Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument ...

CVSS3: 6.1
github
около 4 лет назад

Cross-site Scripting in python-cjson

4.3 Medium

CVSS2