Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2010-2276

Disclosure Date: June 15, 2010 (last updated October 04, 2023)
The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=true and mini=false options, which makes it easier for remote attackers to have an unspecified impact via a request to a (1) test or (2) demo component.
0
Attacker Value
Unknown

CVE-2010-2275

Disclosure Date: June 15, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html.
0
Attacker Value
Unknown

CVE-2010-2272

Disclosure Date: June 15, 2010 (last updated October 04, 2023)
Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2008-6681

Disclosure Date: April 09, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in dijit.Editor in Dojo before 1.1 allows remote attackers to inject arbitrary web script or HTML via XML entities in a TEXTAREA element.
0
Attacker Value
Unknown

CVE-2007-6726

Disclosure Date: April 09, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
0