CVE-2012-6684

RedCloth < 4.2.9 - Cross-Site Scripting via JavaScript URI

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.

References (5)

Core 5
Core References
Broken Link x_refsource_misc
http://co3k.org/blog/redcloth-unfixed-xss-en
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/50
Issue Tracking, Patch x_refsource_misc
https://gist.github.com/co3k/75b3cb416c342aa1414c
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3168

Scores

EPSS 0.0059
EPSS Percentile 69.4%

Details

CWE
CWE-79
Status published
Products (3)
debian/debian_linux 7.0
redcloth/redcloth_library < 4.2.9
rubygems/RedCloth 0 - 4.3.0RubyGems
Published Jan 08, 2015
Tracked Since Feb 18, 2026