CVE-2005-1638

Publication date

2005-05-17 04:00:00

Family

mitre

State

PUBLISHED

Description

The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.