CVE-2013-0256

EUVD-2017-0308
darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
ruby-langrdoc
2.3.0 ≤
𝑥
< 3.12
ruby-langrdoc
4.0.0:preview2
ruby-langruby
1.9
ruby-langruby
1.9.1
ruby-langruby
1.9.2
ruby-langruby
1.9.3
ruby-langruby
1.9.3:p0
ruby-langruby
1.9.3:p125
ruby-langruby
1.9.3:p194
ruby-langruby
1.9.3:p286
ruby-langruby
1.9.3:p383
ruby-langruby
2.0
ruby-langruby
2.0.0
ruby-langruby
2.0.0:rc1
ruby-langruby
2.0.0:rc2
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby-defaults
hardy
ignored
lucid
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
ruby1.8
hardy
ignored
lucid
ignored
oneiric
ignored
precise
ignored
quantal
ignored
raring
ignored
ruby1.9
hardy
ignored
lucid
ignored
maverick
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
ruby1.9.1
hardy
dne
lucid
ignored
oneiric
ignored
precise
Fixed 1.9.3.0-1ubuntu2.5
released
quantal
Fixed 1.9.3.194-1ubuntu1.3
released
raring
Fixed 1.9.3.194-7ubuntu1
released