CVE-2010-2275
15.06.2010, 14:30
Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html.
Vendor | Product | Version |
---|---|---|
dojotoolkit | dojo | 𝑥 ≤ 1.4.1 |
dojotoolkit | dojo | 0.1.0 |
dojotoolkit | dojo | 0.2.0 |
dojotoolkit | dojo | 0.2.1 |
dojotoolkit | dojo | 0.2.2 |
dojotoolkit | dojo | 0.3.0 |
dojotoolkit | dojo | 0.3.1 |
dojotoolkit | dojo | 0.4.0 |
dojotoolkit | dojo | 0.4.1 |
dojotoolkit | dojo | 0.4.2 |
dojotoolkit | dojo | 0.4.3 |
dojotoolkit | dojo | 0.9.0 |
dojotoolkit | dojo | 0.9.0:beta |
dojotoolkit | dojo | 1.0 |
dojotoolkit | dojo | 1.0.1 |
dojotoolkit | dojo | 1.0.2 |
dojotoolkit | dojo | 1.1 |
dojotoolkit | dojo | 1.1.1 |
dojotoolkit | dojo | 1.2 |
dojotoolkit | dojo | 1.2.1 |
dojotoolkit | dojo | 1.2.2 |
dojotoolkit | dojo | 1.2.3 |
dojotoolkit | dojo | 1.3 |
dojotoolkit | dojo | 1.3.1 |
dojotoolkit | dojo | 1.3.2 |
dojotoolkit | dojo | 1.4 |
𝑥
= Vulnerable software versions

Debian Releases
References