Lucene search

K
nvd[email protected]NVD:CVE-2013-0256
HistoryMar 01, 2013 - 5:40 a.m.

CVE-2013-0256

2013-03-0105:40:17
CWE-79
web.nvd.nist.gov

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.1%

darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

Affected configurations

NVD
Node
ruby-langrdocRange2.3.03.12ruby
OR
ruby-langrdocMatch4.0.0preview2ruby
OR
ruby-langrubyMatch1.9
OR
ruby-langrubyMatch1.9.1
OR
ruby-langrubyMatch1.9.2
OR
ruby-langrubyMatch1.9.3
OR
ruby-langrubyMatch1.9.3p0
OR
ruby-langrubyMatch1.9.3p125
OR
ruby-langrubyMatch1.9.3p194
OR
ruby-langrubyMatch1.9.3p286
OR
ruby-langrubyMatch1.9.3p383
OR
ruby-langrubyMatch2.0
OR
ruby-langrubyMatch2.0.0
OR
ruby-langrubyMatch2.0.0rc1
OR
ruby-langrubyMatch2.0.0rc2
Node
canonicalubuntu_linuxMatch12.04-
OR
canonicalubuntu_linuxMatch12.10

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.1%