CVE-2010-2273: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to dojo/resources/iframehistory.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, and util/buildscripts/jslib/buildUtil.js, as demonstrated by the (1) dojoUrl and (2) testUrl parameters to util/doh/runner.html.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2273?
CVE-2010-2273 has a moderate severity level due to its ability to allow cross-site scripting attacks.
How do I fix CVE-2010-2273?
To fix CVE-2010-2273, you should upgrade to Dojo versions 1.0.3, 1.1.2, 1.2.4, 1.3.3, or 1.4.2 or later.
What types of vulnerabilities are associated with CVE-2010-2273?
CVE-2010-2273 is associated with multiple cross-site scripting (XSS) vulnerabilities.
Which versions of Dojo are affected by CVE-2010-2273?
CVE-2010-2273 affects Dojo versions 1.0.x up to 1.0.2, 1.1.x up to 1.1.1, 1.2.x up to 1.2.3, 1.3.x up to 1.3.2, and 1.4.x up to 1.4.1.
What is the impact of CVE-2010-2273 on web applications?
The impact of CVE-2010-2273 on web applications includes the potential for attackers to inject arbitrary web scripts or HTML, leading to a compromise of user data.