4.3

CVE-2010-1195

Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IkiwikiIkiwiki Version2.0
IkiwikiIkiwiki Version2.1
IkiwikiIkiwiki Version2.2
IkiwikiIkiwiki Version2.3
IkiwikiIkiwiki Version2.4
IkiwikiIkiwiki Version2.5
IkiwikiIkiwiki Version2.10
IkiwikiIkiwiki Version2.11
IkiwikiIkiwiki Version2.12
IkiwikiIkiwiki Version2.13
IkiwikiIkiwiki Version2.14
IkiwikiIkiwiki Version2.15
IkiwikiIkiwiki Version2.16
IkiwikiIkiwiki Version2.17
IkiwikiIkiwiki Version2.18
IkiwikiIkiwiki Version2.19
IkiwikiIkiwiki Version2.20
IkiwikiIkiwiki Version2.30
IkiwikiIkiwiki Version2.31
IkiwikiIkiwiki Version2.31.1
IkiwikiIkiwiki Version2.31.2
IkiwikiIkiwiki Version2.31.3
IkiwikiIkiwiki Version2.40
IkiwikiIkiwiki Version2.41
IkiwikiIkiwiki Version2.42
IkiwikiIkiwiki Version2.43
IkiwikiIkiwiki Version2.44
IkiwikiIkiwiki Version2.45
IkiwikiIkiwiki Version2.46
IkiwikiIkiwiki Version2.47
IkiwikiIkiwiki Version2.48
IkiwikiIkiwiki Version2.49
IkiwikiIkiwiki Version2.50
IkiwikiIkiwiki Version2.51
IkiwikiIkiwiki Version2.52
IkiwikiIkiwiki Version2.53
IkiwikiIkiwiki Version3.00
IkiwikiIkiwiki Version3.01
IkiwikiIkiwiki Version3.02
IkiwikiIkiwiki Version3.03
IkiwikiIkiwiki Version3.04
IkiwikiIkiwiki Version3.05
IkiwikiIkiwiki Version3.06
IkiwikiIkiwiki Version3.07
IkiwikiIkiwiki Version3.08
IkiwikiIkiwiki Version3.09
IkiwikiIkiwiki Version3.10
IkiwikiIkiwiki Version3.11
IkiwikiIkiwiki Version3.12
IkiwikiIkiwiki Version3.13
IkiwikiIkiwiki Version3.14
IkiwikiIkiwiki Version3.141
IkiwikiIkiwiki Version3.1415
IkiwikiIkiwiki Version3.14159
IkiwikiIkiwiki Version3.141592
IkiwikiIkiwiki Version3.1415926
IkiwikiIkiwiki Version3.14159265
IkiwikiIkiwiki Version3.20091009
IkiwikiIkiwiki Version3.20091017
IkiwikiIkiwiki Version3.20091022
IkiwikiIkiwiki Version3.20091023
IkiwikiIkiwiki Version3.20091031
IkiwikiIkiwiki Version3.20091113
IkiwikiIkiwiki Version3.20091202
IkiwikiIkiwiki Version3.20091218
IkiwikiIkiwiki Version3.20100102.3
IkiwikiIkiwiki Version3.20100122
IkiwikiIkiwiki Version3.20100212
IkiwikiIkiwiki Version3.20100302
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.519
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.