CVE-2010-2275

Dojo < 1.4.1 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Adam Bixby · textwebappsmultiple
https://www.exploit-db.com/exploits/33764

Scores

EPSS 0.1782
EPSS Percentile 95.1%

Classification

CWE
CWE-79
Status published

Affected Products (27)

dojotoolkit/dojo < 1.4.1
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
dojotoolkit/dojo
... and 12 more

Timeline

Published Jun 15, 2010
Tracked Since Feb 18, 2026