Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2010-5312 - CERT CVE
CVE-2010-5312
ID
CVE-2010-5312
Sažetak
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
Reference
https://github.com/jquery/jquery-ui/commit/7e9060c109b928769a664dbcc2c17bd21231b6f3
http://seclists.org/oss-sec/2014/q4/616
http://bugs.jqueryui.com/ticket/6016
http://seclists.org/oss-sec/2014/q4/613
http://rhn.redhat.com/errata/RHSA-2015-0442.html
http://www.debian.org/security/2015/dsa-3249
http://www.securityfocus.com/bid/71106
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
http://rhn.redhat.com/errata/RHSA-2015-1462.html
http://www.securitytracker.com/id/1037035
https://exchange.xforce.ibmcloud.com/vulnerabilities/98696
https://security.netapp.com/advisory/ntap-20190416-0007/
https://lists.debian.org/debian-lts-announce/2022/01/msg00014.html
https://www.drupal.org/sa-core-2022-002
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
CVSS
Base:
4.3
Impact:
2.9
Exploitability:
8.6
Pristup
Vektor
Složenost
Autentikacija
NETWORK
MEDIUM
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
NONE
PARTIAL
NONE
CVSS vektor
AV:N/AC:M/Au:N/C:N/I:P/A:N
Zadnje važnije ažuriranje
21-06-2023 - 18:26
Objavljeno
24-11-2014 - 16:59