CVE-2010-2480

Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:makotemplates:mako:*:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.0:-:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.3:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.4:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.5:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.6:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.7:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.8:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.9:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.1.10:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.3:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.4:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.5:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.2.6:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.3:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:makotemplates:mako:0.3.2:*:*:*:*:*:*:*

History

13 Feb 2023, 04:21

Type Values Removed Values Added
Summary CVE-2010-2480 Python-Mako (prior v0.3.4): Improper escaping of single quotes in escape.cgi (XSS) Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=609573', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=609573', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2010-2480', 'name': 'https://access.redhat.com/security/cve/CVE-2010-2480', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 15:15

Type Values Removed Values Added
References
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=609573 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2010-2480 -
Summary Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element. CVE-2010-2480 Python-Mako (prior v0.3.4): Improper escaping of single quotes in escape.cgi (XSS)

Information

Published : 2010-07-02 19:00

Updated : 2023-12-10 11:03


NVD link : CVE-2010-2480

Mitre link : CVE-2010-2480

CVE.ORG link : CVE-2010-2480


JSON object : View

Products Affected

makotemplates

  • mako
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')