CVE-2012-6662 – jquery-ui: XSS vulnerability in default content in Tooltip widget
https://notcve.org/view.php?id=CVE-2012-6662
Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo. Vulnerabilidad de XSS en la opción de contenido por defecto en jquery.ui.tooltip.js en el widget Tooltip en jQuery UI anterior a 1.10.0 permite a atacantes remotos inyectar secuencias de comandos web o HTMl arbitrarios a través del atributo del título, lo cual no se maneja debidamente en la demostración de cuadros combinados del autocompletado. • http://bugs.jqueryui.com/ticket/8859 http://bugs.jqueryui.com/ticket/8861 http://rhn.redhat.com/errata/RHSA-2015-0442.html http://rhn.redhat.com/errata/RHSA-2015-1462.html http://seclists.org/oss-sec/2014/q4/613 http://seclists.org/oss-sec/2014/q4/616 http://www.securityfocus.com/bid/71107 https://exchange.xforce.ibmcloud.com/vulnerabilities/98697 https://github.com/jquery/jquery-ui/commit/5fee6fd5000072ff32f2d65b6451f39af9e0e39e https://github.com/jquery/jquery-ui/commit/ • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •