CVE-2010-2479
Published: 6 July 2010
Cross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Priority
Status
Package | Release | Status |
---|---|---|
mahara Launchpad, Ubuntu, Debian |
upstream |
Released
(1.0.15,1.1.9,1.2.5)
|
dapper |
Does not exist
|
|
hardy |
Does not exist
|
|
jaunty |
Released
(1.0.9-2ubuntu0.7)
|
|
karmic |
Released
(1.1.5-1ubuntu0.3)
|
|
lucid |
Released
(1.2.4-1ubuntu0.1)
|
|
maverick |
Released
(1.2.5-2)
|
|
natty |
Released
(1.2.5-2)
|
|
Patches: upstream: http://repo.or.cz/w/htmlpurifier.git/commitdiff/18e538317a877a0509ae71a860429c41770da230 debdiff: https://bugs.launchpad.net/ubuntu/+source/mahara/+bug/602772 |
||
php-htmlpurifier Launchpad, Ubuntu, Debian |
upstream |
Released
(4.1.1)
|
dapper |
Does not exist
|
|
hardy |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Released
(3.3.0-1ubuntu0.1)
|
|
lucid |
Released
(4.0.0+dfsg1-1ubuntu0.1)
|
|
maverick |
Not vulnerable
(4.1.1+dfsg1-1)
|
|
natty |
Not vulnerable
(4.1.1+dfsg1-1)
|
|
Patches: upstream: http://repo.or.cz/w/htmlpurifier.git/commitdiff/18e538317a877a0509ae71a860429c41770da230 |