CVE Vulnerabilities

CVE-2005-4454

Published: Dec 21, 2005 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a (backslash) within a javascript scheme in a style property (such as javascript), which bypasses the javascript check before the is stripped and then rendered in web browsers that allow scripting in style sheets.

Affected Software

Name Vendor Start Version End Version
Livejournal Livejournal * *

References