The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-05-17T04:00:00Z

Updated: 2024-09-16T22:01:47.046Z

Reserved: 2005-05-17T00:00:00Z

Link: CVE-2005-1638

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-05-17T04:00:00.000

Modified: 2008-09-05T20:49:40.467

Link: CVE-2005-1638

cve-icon Redhat

No data.