CVE-2010-2480

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:makotemplates:mako:*:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.0:-:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.3:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.4:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.5:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.6:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.7:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.8:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.9:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.10:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.3:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.4:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.5:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.6:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.3:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.3.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-07-02 19:00

Updated : 2024-02-04 17:54


NVD link : CVE-2010-2480

Mitre link : CVE-2010-2480

CVE.ORG link : CVE-2010-2480


JSON object : View

Products Affected

makotemplates

  • mako
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')