299,749
Total vulnerabilities in the database
Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field.
| Software | From | Fixed in |
|---|---|---|
| open_source_development_network / slashcode | - | 1.0.8.x |
| open_source_development_network / slashcode | 2.0 | 2.0.x |
| open_source_development_network / slashcode | 2.2.3 | 2.2.3.x |
| open_source_development_network / slashcode | 2.2 | 2.2.x |
| open_source_development_network / slashcode | 2.1 | 2.1.x |
| open_source_development_network / slashcode | 2.2.1 | 2.2.1.x |
| open_source_development_network / slashcode | 2.1.1 | 2.1.1.x |
| open_source_development_network / slashcode | 2.2.2 | 2.2.2.x |
| open_source_development_network / slashcode | 2.2.4 | 2.2.4.x |