CVE Database
/

CVE-2005-4454

Back to search

CVE-2005-4454

Published: Dec 21, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a "\" (backslash) within a "javascript" scheme in a style property (such as "javas\cript"), which bypasses the "javascript" check before the "\" is stripped and then rendered in web browsers that allow scripting in style sheets.

VendorProductVersions

n/a

n/a

affected
n/a

References

18157
third-party-advisory
x_refsource_SECUNIA
21896
vdb-entry
x_refsource_OSVDB
livejournal-javascript-xss(23839)
vdb-entry
x_refsource_XF
15990
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now