Security Advisory

CVE-2010-1330

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-11-23 19:00:00
Last updated 2024-08-07 01:21:18
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.