Lucene search

K
prionPRIOn knowledge basePRION:CVE-2007-0242
HistoryApr 03, 2007 - 4:19 p.m.

Cross site scripting

2007-04-0316:19:00
PRIOn knowledge base
www.prio-n.com
4

5.5 Medium

AI Score

Confidence

High

0.032 Low

EPSS

Percentile

91.2%

The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.

CPENameOperatorVersion
qteq3.3.8
qteq4.2.3

References