CVE Vulnerabilities

CVE-2005-1638

Published: May 17, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.

Affected Software

Name Vendor Start Version End Version
Safehtml Pixel-apes_group 1.1.0 (including) 1.1.0 (including)
Safehtml Pixel-apes_group 1.2.0 (including) 1.2.0 (including)
Safehtml Pixel-apes_group 1.2.1 (including) 1.2.1 (including)
Safehtml Pixel-apes_group 1.3.0 (including) 1.3.0 (including)
Safehtml Pixel-apes_group 1.3.1 (including) 1.3.1 (including)

References