Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Software | From | Fixed in |
---|---|---|
directwebremoting / direct_web_remoting | 3.0-rc1 | 3.0-rc1.x |
directwebremoting / direct_web_remoting | - | 2.0.10.x |
directwebremoting / direct_web_remoting | 3.0-rc2 | 3.0-rc2.x |
![]() |
- | 2.0.11 |
![]() |
3.0.M1 | 3.0.RC3 |