Dojotoolkit

Dojo

11 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Published 06.09.2018 17:29:01
  • Last modified 21.11.2024 03:40:21

Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can re...

  • EPSS 0.69%
  • Published 18.08.2018 02:29:01
  • Last modified 21.11.2024 03:50:56

In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

Exploit
  • EPSS 0.2%
  • Published 02.02.2018 15:29:00
  • Last modified 21.11.2024 04:10:54

dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.

  • EPSS 0.25%
  • Published 11.10.2015 01:59:03
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.46%
  • Published 15.06.2010 14:30:01
  • Last modified 11.04.2025 00:51:21

Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors.

Exploit
  • EPSS 21.46%
  • Published 15.06.2010 14:30:01
  • Last modified 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, ...

  • EPSS 0.91%
  • Published 15.06.2010 14:30:01
  • Last modified 11.04.2025 00:51:21

Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via uns...

Exploit
  • EPSS 16.21%
  • Published 15.06.2010 14:30:01
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test...

  • EPSS 2.64%
  • Published 15.06.2010 14:30:01
  • Last modified 11.04.2025 00:51:21

The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=true and mini=false options, which makes it easier for...

  • EPSS 1.5%
  • Published 09.04.2009 15:08:35
  • Last modified 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_...