PT-2010-2820 · Zope+1 · Zope+1

Publicado

2010-03-25

·

Atualizado

2019-11-25

·

CVE-2010-1104

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zope versions 2.8.x through 2.8.11 Zope versions 2.9.x through 2.9.11 Zope versions 2.10.x through 2.10.10 Zope versions 2.11.x through 2.11.5 Zope versions 2.12.x through 2.12.2
Description The issue allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages, which can lead to cross-site scripting (XSS).
Recommendations For Zope versions 2.8.x through 2.8.11, update to version 2.8.12 or later. For Zope versions 2.9.x through 2.9.11, update to version 2.9.12 or later. For Zope versions 2.10.x through 2.10.10, update to version 2.10.11 or later. For Zope versions 2.11.x through 2.11.5, update to version 2.11.6 or later. For Zope versions 2.12.x through 2.12.2, update to version 2.12.3 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1104
GHSA-V7Q8-WVVH-C97P
RHSA-2012:0151
RHSA-2012_0151

Produtos afetados

Red Hat
Zope