CVE Vulnerabilities

CVE-2010-2274

Published: Jun 15, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.

Affected Software

Name Vendor Start Version End Version
Dojo Dojotoolkit 1.0 (including) 1.0 (including)
Dojo Dojotoolkit 1.0.1 (including) 1.0.1 (including)
Dojo Dojotoolkit 1.0.2 (including) 1.0.2 (including)
Dojo Dojotoolkit 1.1 (including) 1.1 (including)
Dojo Dojotoolkit 1.1.1 (including) 1.1.1 (including)
Dojo Dojotoolkit 1.2 (including) 1.2 (including)
Dojo Dojotoolkit 1.2.1 (including) 1.2.1 (including)
Dojo Dojotoolkit 1.2.2 (including) 1.2.2 (including)
Dojo Dojotoolkit 1.2.3 (including) 1.2.3 (including)
Dojo Dojotoolkit 1.3 (including) 1.3 (including)
Dojo Dojotoolkit 1.3.1 (including) 1.3.1 (including)
Dojo Dojotoolkit 1.3.2 (including) 1.3.2 (including)
Dojo Dojotoolkit 1.4 (including) 1.4 (including)
Dojo Dojotoolkit 1.4.1 (including) 1.4.1 (including)
Dojo Ubuntu upstream *

References