Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2010-2275

Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html.

  • Published: Jun 15, 2010
  • Updated: Apr 13, 2023
  • CVE: CVE-2010-2275
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
dojotoolkit / dojo 1.2.1 1.2.1.x
dojotoolkit / dojo 1.1 1.1.x
dojotoolkit / dojo 0.4.3 0.4.3.x
dojotoolkit / dojo - 1.4.1.x
dojotoolkit / dojo 0.3.1 0.3.1.x
dojotoolkit / dojo 0.2.2 0.2.2.x
dojotoolkit / dojo 1.3.2 1.3.2.x
dojotoolkit / dojo 0.3.0 0.3.0.x
dojotoolkit / dojo 0.9.0-beta 0.9.0-beta.x
dojotoolkit / dojo 0.4.0 0.4.0.x
dojotoolkit / dojo 0.9.0 0.9.0.x
dojotoolkit / dojo 0.4.1 0.4.1.x
dojotoolkit / dojo 1.0.1 1.0.1.x
dojotoolkit / dojo 1.2.3 1.2.3.x
dojotoolkit / dojo 1.0 1.0.x
dojotoolkit / dojo 1.3.1 1.3.1.x
dojotoolkit / dojo 1.0.2 1.0.2.x
dojotoolkit / dojo 1.1.1 1.1.1.x
dojotoolkit / dojo 1.3 1.3.x
dojotoolkit / dojo 0.1.0 0.1.0.x
dojotoolkit / dojo 0.4.2 0.4.2.x
dojotoolkit / dojo 1.2.2 1.2.2.x
dojotoolkit / dojo 0.2.0 0.2.0.x
dojotoolkit / dojo 1.2 1.2.x
dojotoolkit / dojo 0.2.1 0.2.1.x
dojotoolkit / dojo 1.4 1.4.x