Описание
Multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) name or (2) email value.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | ignored | end of life |
| devel | not-affected | 2.3.14.1 |
| hardy | ignored | end of life |
| karmic | ignored | end of life |
| lucid | released | 2.2.3-2ubuntu0.1 |
| maverick | released | 2.3.5-1.1ubuntu0.1 |
| natty | released | 2.3.5-1.2ubuntu1.1 |
| upstream | released | 2.3.11,3.0.4 |
Показывать по
10
EPSS
Процентиль: 71%
0.0067
Низкий
4.3 Medium
CVSS2
Связанные уязвимости
nvd
почти 15 лет назад
Multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) name or (2) email value.
debian
почти 15 лет назад
Multiple cross-site scripting (XSS) vulnerabilities in the mail_to hel ...
EPSS
Процентиль: 71%
0.0067
Низкий
4.3 Medium
CVSS2