Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-1855
Description:The sanitize_css method in lib/action_controller/vendor/html- scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-1855
APPLE-SA-2013-06-04-1
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
APPLE-SA-2013-10-22-5
http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html
RHSA-2013:0698
http://rhn.redhat.com/errata/RHSA-2013-0698.html
RHSA-2014:1863
http://rhn.redhat.com/errata/RHSA-2014-1863.html
[rubyonrails-security] 20130318 [CVE-2013-1855] XSS vulnerability in sanitize_css in Action Pack
https://groups.google.com/group/rubyonrails-security/msg/8ed835a97cdd1afd?dmode=source&output=gplain
http://support.apple.com/kb/HT5784
http://support.apple.com/kb/HT5784
http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/
http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/
openSUSE-SU-2013:0661
http://lists.opensuse.org/opensuse-updates/2013-04/msg00072.html
openSUSE-SU-2013:0662
http://lists.opensuse.org/opensuse-updates/2013-04/msg00073.html
openSUSE-SU-2014:0019
http://lists.opensuse.org/opensuse-updates/2014-01/msg00013.html




© 1998-2025 E-Soft Inc. All rights reserved.