CVE-2005-4454

Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a "\" (backslash) within a "javascript" scheme in a style property (such as "javas\cript"), which bypasses the "javascript" check before the "\" is stripped and then rendered in web browsers that allow scripting in style sheets.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:livejournal:livejournal:*:*:*:*:*:*:*:*

Information

Published : 2005-12-21 03:03

Updated : 2017-07-19 18:29


NVD link : CVE-2005-4454

Mitre link : CVE-2005-4454


JSON object : View

Advertisement

dedicated server usa

Products Affected

livejournal

  • livejournal