Описание
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "", which results in the enclosed script logic to be executed.
Релиз | Статус | Примечание |
---|---|---|
bionic | not-affected | 3.2.1-1 |
devel | not-affected | 3.3.1~dfsg-3 |
eoan | ignored | end of life |
esm-infra-legacy/trusty | ignored | |
esm-infra/bionic | not-affected | 3.2.1-1 |
esm-infra/focal | not-affected | 3.3.1~dfsg-3 |
esm-infra/xenial | ignored | |
focal | not-affected | 3.3.1~dfsg-3 |
precise/esm | ignored | |
trusty | ignored | end of standard support |
Показывать по
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load ...
Уязвимость библиотеки jQuery, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить межсайтовую сценарную атаку
4.3 Medium
CVSS2
6.1 Medium
CVSS3