![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-4409
https://notcve.org/view.php?id=CVE-2013-4409
04 Nov 2019 — An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. Existe una vulnerabilidad de la función eval() en Python Software Foundation Djblets versión 0.7.21 y Beanbag Review Board versiones anteriores a la versión 1.7.15, cuando se analizan peticiones JSON. • http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120619.html • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-4312
https://notcve.org/view.php?id=CVE-2011-4312
24 Nov 2011 — Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) diff viewer or (2) screenshot component. Multiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en el sistema de comentarios de Review Board antes de v1.5.7 y 1.6.x antes de v1.6.3 permite a atacantes remotos inyectar secuencias de comandos web o HTML a t... • http://lists.fedoraproject.org/pipermail/package-announce/2011-November/070091.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •