Skip to content

TechMedia

Header Image
Archive

Month: March 2018

2 Posts

Featured

Posted byWpmaster
[sanitize] Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
Posted byWpmaster
[rack-protection] rack-protection Observable Discrepancy vulnerability

[sanitize] Sanitize vulnerable to Improper Input Validation and Cross-site Scripting

  • Posted inHIGH
  • Posted byWpmaster
  • 03/21/201810/20/2022

When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements.
This can allow…

[rack-protection] rack-protection Observable Discrepancy vulnerability

  • Posted inMODERATE
  • Posted byWpmaster
  • 03/08/201801/26/2023

Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby a…

TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close