V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2013-0256
DEB
Medium

darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows…

CVSS
5.0
Medium
EPSS
0.04
p87
Published
2013-01-01
Updated
2013-01-01
Description

darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

Tags · CWE
XSS
CWE-79
CAPEC-63
CAPEC-85
CAPEC-209
CAPEC-588
CAPEC-591
CAPEC-592
Affected products
CandlepinKatelloKatello-configureRuby-defaultsRuby1.8Ruby1.8Ruby1.9Ruby1.9.1Ruby193-rubyRuby193-rubygem-activesupportRuby193-rubygem-bcrypt-rubyRuby193-rubygem-bsonRuby193-rubygem-chunky_pngRuby193-rubygem-ci_reporterRuby193-rubygem-compassRuby193-rubygem-fastthreadRuby193-rubygem-hamlRuby193-rubygem-http_connectionRuby193-rubygem-rackRuby193-rubygem-rack-test
CVSS vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Timeline
2013-01-01
Published
2013-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.036 · p87
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
candlepinTracked
katelloTracked
katello-configureTracked
ruby-defaultsTracked
ruby1.8Tracked
ruby1.8Tracked
ruby1.9Tracked
ruby1.9.1Tracked
ruby193-rubyTracked
ruby193-rubygem-activesupportTracked
ruby193-rubygem-bcrypt-rubyTracked
ruby193-rubygem-bsonTracked
ruby193-rubygem-chunky_pngTracked
ruby193-rubygem-ci_reporterTracked
ruby193-rubygem-compassTracked
ruby193-rubygem-fastthreadTracked
ruby193-rubygem-hamlTracked
ruby193-rubygem-http_connectionTracked
ruby193-rubygem-rackTracked
ruby193-rubygem-rack-testTracked
Showing first 20 of 46
Source databases
DEB
CVE
RED
UBU