The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2014-07-26T15:00:00
Updated: 2024-08-06T10:28:46.194Z
Reserved: 2014-04-21T00:00:00
Link: CVE-2014-2966
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-07-26T15:55:03.527
Modified: 2024-11-21T02:07:15.297
Link: CVE-2014-2966
Redhat
No data.