Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-6416

Опубликовано: 07 дек. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

РелизСтатусПримечание
devel

not-affected

contains no code
lucid

not-affected

precise

not-affected

contains no code
quantal

not-affected

contains no code
raring

not-affected

contains no code
saucy

not-affected

contains no code
upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

not-affected

lucid

DNE

precise

not-affected

quantal

not-affected

raring

not-affected

saucy

not-affected

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

not-affected

lucid

DNE

precise

DNE

quantal

not-affected

raring

not-affected

saucy

not-affected

upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

not-affected

lucid

DNE

precise

not-affected

quantal

not-affected

raring

not-affected

saucy

not-affected

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

not-affected

lucid

DNE

precise

DNE

quantal

not-affected

raring

not-affected

saucy

not-affected

upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

not-affected

lucid

DNE

precise

not-affected

quantal

not-affected

raring

not-affected

saucy

not-affected

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

not-affected

lucid

DNE

precise

DNE

quantal

not-affected

raring

not-affected

saucy

not-affected

upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

not-affected

lucid

DNE

precise

not-affected

quantal

not-affected

raring

not-affected

saucy

not-affected

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

not-affected

lucid

DNE

precise

DNE

quantal

not-affected

raring

not-affected

saucy

not-affected

upstream

not-affected

Показывать по

EPSS

Процентиль: 46%
0.00236
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

nvd
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

debian
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the simple_format helper i ...

github
больше 8 лет назад

actionpack Cross-site Scripting vulnerability

EPSS

Процентиль: 46%
0.00236
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2013-6416