CVE-2009-4924
python-cjson < 1.1.0 - Cross-Site Scripting via cjson.encode Function
Title source: llmDescription
Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.
References (2)
Core 2
Core References
Various Sources x_refsource_misc
http://pypi.python.org/pypi/python-cjson/
Various Sources x_refsource_misc
http://t3.dotgnu.info/blog/insecurity/quotes-dont-help.html
Scores
EPSS
0.0135
EPSS Percentile
68.7%
Details
CWE
CWE-79
Status
published
Products (2)
dan_pascu/python-cjson
1.0.5
pypi/python-cjson
0 - 1.1.0PyPI
Published
Jul 02, 2010
Tracked Since
Feb 18, 2026