CVE-2010-2276
Summary
| CVE | CVE-2010-2276 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-06-15 14:30:00 UTC |
| Updated | 2010-06-16 14:03:00 UTC |
| Description | The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=true and mini=false options, which makes it easier for remote attackers to have an unspecified impact via a request to a (1) test or (2) demo component. |
Risk And Classification
Problem Types: CWE-16
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dojotoolkit | Dojo | 0.4.0 | All | All | All |
| Application | Dojotoolkit | Dojo | 0.4.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 0.4.2 | All | All | All |
| Application | Dojotoolkit | Dojo | 0.4.3 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.0 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.0.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.0.2 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.1.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.2 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.2.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.2.2 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.2.3 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.3 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.3.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.3.2 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.4 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.4.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 0.4.0 | All | All | All |
| Application | Dojotoolkit | Dojo | 0.4.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 0.4.2 | All | All | All |
| Application | Dojotoolkit | Dojo | 0.4.3 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.0 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.0.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.0.2 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.1.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.2 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.2.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.2.2 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.2.3 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.3 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.3.1 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.3.2 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.4 | All | All | All |
| Application | Dojotoolkit | Dojo | 1.4.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| LO50958: DOJO SECURITY PATCH AFFECTING DOJO 1.1.1, 1.1.0 AND 1.2.3 | AIXAPAR | www-1.ibm.com | |
| LO50856: DOJO SECURITY PATCH AFFECTING DOJO 1.1.1, 1.1.0 AND 1.2.3 | AIXAPAR | www-1.ibm.com | |
| Dojo Toolkit Redirection Weaknesses and Cross-Site Scripting - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| LO50896: DOJO SECURITY PATCH AFFECTING DOJO 1.1.1, 1.1.0 AND 1.2.3 | AIXAPAR | www-1.ibm.com | |
| IBM Fix List and installation instructions for Lotus Connections 2.5.0 Fix Pack 2 (2.5.0.2) - United States | CONFIRM | www-01.ibm.com | |
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-1.ibm.com | |
| Page not found | The Dojo Toolkit Blog | CONFIRM | dojotoolkit.org | Patch, Vendor Advisory |
| LO50994: DOJO SECURITY PATCH AFFECTING DOJO 1.1.1, 1.1.0 AND 1.2.3 | AIXAPAR | www-1.ibm.com | |
| IBM Lotus Connections Multiple Vulnerabilities - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| LO50849: DOJO SECURITY PATCH AFFECTING DOJO 1.1.1, 1.1.0 AND 1.2.3 | AIXAPAR | www-1.ibm.com | |
| LO50833: DOJO SECURITY PATCH AFFECTING DOJO 1.1.1, 1.1.0 AND 1.2.3 | AIXAPAR | www-1.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.