Описание
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.3.5-1 |
| esm-infra-legacy/trusty | released | 3.3.3-1ubuntu0.1 |
| lucid | ignored | end of life |
| precise | released | 2.3.2-1ubuntu0.2 |
| quantal | ignored | end of life |
| saucy | released | 3.2.0-1ubuntu0.1 |
| trusty | released | 3.3.3-1ubuntu0.1 |
| trusty/esm | released | 3.3.3-1ubuntu0.1 |
| upstream | released | 3.3.5 |
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
Incomplete blacklist vulnerability in the lxml.html.clean module in lx ...
lxml Cross-site Scripting Via Control Characters
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить целостность защищаемой информации
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3