1 results (0.001 seconds)

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 2

Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed. Vulnerabildiad de Secuencias de Comandos en Sitios Cruzados (XSS) en Planet v2.0 y Planet Venus, permite a atacantes remotos inyectar secuencias de comandos Web o HTML de su elección a través del atributo SRC en un elemento IMG en una fuente. • https://www.exploit-db.com/exploits/33219 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=546178 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=546179 http://intertwingly.net/blog/2009/09/09/Venus-Updates http://lists.planetplanet.org/archives/devel/2009-September/001999.html http://secunia.com/advisories/36636 http://secunia.com/advisories/36766 http://www.securityfocus.com/bid/36392 https://bugzilla.redhat.com/show_bug.cgi?id=522802 https://www.redhat.com/archives • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •