4.3

CVE-2011-1841

Cross-site scripting (XSS) vulnerability in the link_to helper in Mojolicious before 1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MojoliciousMojolicious Version <= 1.11
MojoliciousMojolicious Version0.2
MojoliciousMojolicious Version0.3
MojoliciousMojolicious Version0.4
MojoliciousMojolicious Version0.5
MojoliciousMojolicious Version0.6
MojoliciousMojolicious Version0.7
MojoliciousMojolicious Version0.8
MojoliciousMojolicious Version0.8.1
MojoliciousMojolicious Version0.8.2
MojoliciousMojolicious Version0.8.3
MojoliciousMojolicious Version0.8.4
MojoliciousMojolicious Version0.8.5
MojoliciousMojolicious Version0.9
MojoliciousMojolicious Version0.8006
MojoliciousMojolicious Version0.8007
MojoliciousMojolicious Version0.8008
MojoliciousMojolicious Version0.8009
MojoliciousMojolicious Version0.9001
MojoliciousMojolicious Version0.9002
MojoliciousMojolicious Version0.991231
MojoliciousMojolicious Version0.991232
MojoliciousMojolicious Version0.991233
MojoliciousMojolicious Version0.991234
MojoliciousMojolicious Version0.991235
MojoliciousMojolicious Version0.991236
MojoliciousMojolicious Version0.991237
MojoliciousMojolicious Version0.991238
MojoliciousMojolicious Version0.991239
MojoliciousMojolicious Version0.991240
MojoliciousMojolicious Version0.991241
MojoliciousMojolicious Version0.991242
MojoliciousMojolicious Version0.991243
MojoliciousMojolicious Version0.991244
MojoliciousMojolicious Version0.991245
MojoliciousMojolicious Version0.991246
MojoliciousMojolicious Version0.991250
MojoliciousMojolicious Version0.991251
MojoliciousMojolicious Version0.999901
MojoliciousMojolicious Version0.999902
MojoliciousMojolicious Version0.999903
MojoliciousMojolicious Version0.999904
MojoliciousMojolicious Version0.999905
MojoliciousMojolicious Version0.999906
MojoliciousMojolicious Version0.999907
MojoliciousMojolicious Version0.999908
MojoliciousMojolicious Version0.999909
MojoliciousMojolicious Version0.999910
MojoliciousMojolicious Version0.999911
MojoliciousMojolicious Version0.999912
MojoliciousMojolicious Version0.999913
MojoliciousMojolicious Version0.999914
MojoliciousMojolicious Version0.999920
MojoliciousMojolicious Version0.999921
MojoliciousMojolicious Version0.999922
MojoliciousMojolicious Version0.999923
MojoliciousMojolicious Version0.999924
MojoliciousMojolicious Version0.999925
MojoliciousMojolicious Version0.999926
MojoliciousMojolicious Version0.999927
MojoliciousMojolicious Version0.999928
MojoliciousMojolicious Version0.999929
MojoliciousMojolicious Version0.999930
MojoliciousMojolicious Version0.999931
MojoliciousMojolicious Version0.999932
MojoliciousMojolicious Version0.999933
MojoliciousMojolicious Version0.999934
MojoliciousMojolicious Version0.999935
MojoliciousMojolicious Version0.999936
MojoliciousMojolicious Version0.999937
MojoliciousMojolicious Version0.999938
MojoliciousMojolicious Version0.999939
MojoliciousMojolicious Version0.999940
MojoliciousMojolicious Version0.999941
MojoliciousMojolicious Version0.999950
MojoliciousMojolicious Version1.0
MojoliciousMojolicious Version1.1
MojoliciousMojolicious Version1.01
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.498
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.