Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Slashcode | Open_source_development_network | * | 1.0.8 (including) |
Slashcode | Open_source_development_network | 2.0 (including) | 2.0 (including) |
Slashcode | Open_source_development_network | 2.1 (including) | 2.1 (including) |
Slashcode | Open_source_development_network | 2.1.1 (including) | 2.1.1 (including) |
Slashcode | Open_source_development_network | 2.2 (including) | 2.2 (including) |
Slashcode | Open_source_development_network | 2.2.1 (including) | 2.2.1 (including) |
Slashcode | Open_source_development_network | 2.2.2 (including) | 2.2.2 (including) |
Slashcode | Open_source_development_network | 2.2.3 (including) | 2.2.3 (including) |
Slashcode | Open_source_development_network | 2.2.4 (including) | 2.2.4 (including) |