Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2020-27511

Disclosure Date: June 21, 2021 (last updated November 28, 2024)
An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denial of Service (ReDOS) through stripping crafted HTML tags.
Attacker Value
Unknown

CVE-2020-7993

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.
Attacker Value
Unknown

CVE-2008-7220

Disclosure Date: September 13, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
0
Attacker Value
Unknown

CVE-2007-2383

Disclosure Date: April 30, 2007 (last updated October 04, 2023)
The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."
0