Dojotoolkit

Dojo

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 06.09.2018 17:29:01
  • Zuletzt bearbeitet 21.11.2024 03:40:21

Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can re...

  • EPSS 0.69%
  • Veröffentlicht 18.08.2018 02:29:01
  • Zuletzt bearbeitet 21.11.2024 03:50:56

In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 02.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:54

dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.

  • EPSS 0.25%
  • Veröffentlicht 11.10.2015 01:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.46%
  • Veröffentlicht 15.06.2010 14:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors.

Exploit
  • EPSS 21.46%
  • Veröffentlicht 15.06.2010 14:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, ...

  • EPSS 0.91%
  • Veröffentlicht 15.06.2010 14:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via uns...

Exploit
  • EPSS 16.21%
  • Veröffentlicht 15.06.2010 14:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test...

  • EPSS 2.64%
  • Veröffentlicht 15.06.2010 14:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=true and mini=false options, which makes it easier for...

  • EPSS 1.5%
  • Veröffentlicht 09.04.2009 15:08:35
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_...