Affects all platforms supported by the vulnerable versions.
Description
HTML/Javascript injection. Does not affect Lite versions.
Discovered
November 20, 2010
Resolved
November 22, 2010
Patches Available
3.0.6
2.5.7 Patch Level 4
Workaround
Remove all URL replacements that paste the following characters " ' < > % /
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Patch Was Unnecessary
As of November 24, 2024, it is believed that this issue, at least insofar as the code that was actually patched, was never exploitable, due to interstitial lines of code that already had the side effect of removing the problematic characters.
This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.