CVE-2005-1638

The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pixel-apes_group:safehtml:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:pixel-apes_group:safehtml:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:pixel-apes_group:safehtml:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:pixel-apes_group:safehtml:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:pixel-apes_group:safehtml:1.3.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-05-17 04:00

Updated : 2024-02-04 16:52


NVD link : CVE-2005-1638

Mitre link : CVE-2005-1638

CVE.ORG link : CVE-2005-1638


JSON object : View

Products Affected

pixel-apes_group

  • safehtml