Show filters
50 Total Results
Displaying 41-50 of 50
Sort by:
Attacker Value
Unknown

CVE-2017-16017

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability.
0
Attacker Value
Unknown

CVE-2017-16016

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability.
0
Attacker Value
Unknown

CVE-2018-3741

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately.
Attacker Value
Unknown

CVE-2018-3740

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.
0
Attacker Value
Unknown

CVE-2016-1000237

Disclosure Date: March 12, 2016 (last updated February 21, 2025)
sanitize-html before 1.4.3 has XSS.
Attacker Value
Unknown

CVE-2015-7580

Disclosure Date: February 16, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node.
0
Attacker Value
Unknown

CVE-2015-7579

Disclosure Date: February 16, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class.
0
Attacker Value
Unknown

CVE-2015-7578

Disclosure Date: February 16, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes.
0
Attacker Value
Unknown

CVE-2011-4457

Disclosure Date: November 17, 2011 (last updated October 04, 2023)
OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element.
0
Attacker Value
Unknown

CVE-2002-2034

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The Email Sanitizer before 1.133 for Procmail allows remote attackers to bypass the mail filter and execute arbitrary code via crafted recursive multipart MIME attachments.
0