We found results for “”
WS-2013-0009
Good to know:
Date: September 3, 2010
XSS vulnerability for applications with dynamic titles because title option is not properly escaped before being set in the dom in JQuery.ui.dialog before 1.10.0.
Language: JS
Severity Score
Related Resources (2)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
Upgrade Version
Upgrade to version phpmyadmin/phpmyadmin - 4.7.0;fillup/phpmyadmin-minimal - no_fix;fillup/phpmyadmin-minimal - 4.4.12;korstiaan/drupal-mirror - no_fix;acosf/archersys - 1.0;mapbender/mapquery - 1.1.2131;jQuery.UI.Combined - 1.10.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


