Описание
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.3.5-1 |
| esm-infra-legacy/trusty | released | 3.3.3-1ubuntu0.1 |
| lucid | ignored | end of life |
| precise | released | 2.3.2-1ubuntu0.2 |
| quantal | ignored | end of life |
| saucy | released | 3.2.0-1ubuntu0.1 |
| trusty | released | 3.3.3-1ubuntu0.1 |
| trusty/esm | released | 3.3.3-1ubuntu0.1 |
| upstream | released | 3.3.5 |
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
Incomplete blacklist vulnerability in the lxml.html.clean module in lx ...
lxml Cross-site Scripting Via Control Characters
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить целостность защищаемой информации
EPSS
4.3 Medium
CVSS2