Vulnerability Description
Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dojotoolkit | Dojo | 1.0 |
References
- http://dojotoolkit.org/blog/post/dylan/2010/03/dojo-security-advisory/PatchVendor Advisory
- http://secunia.com/advisories/38964Vendor Advisory
- http://secunia.com/advisories/40007Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21431472
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO50833
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO50849
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO50856
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO50896
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO50932
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO50958
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO50994
- http://www.vupen.com/english/advisories/2010/1281Vendor Advisory
- http://dojotoolkit.org/blog/post/dylan/2010/03/dojo-security-advisory/PatchVendor Advisory
- http://secunia.com/advisories/38964Vendor Advisory
- http://secunia.com/advisories/40007Vendor Advisory
FAQ
What is CVE-2010-2274?
CVE-2010-2274 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitr...
How severe is CVE-2010-2274?
CVE-2010-2274 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2274?
Check the references section above for vendor advisories and patch information. Affected products include: Dojotoolkit Dojo.