{"api_version":"1","generated_at":"2026-07-23T09:40:22+00:00","cve":"CVE-2010-2480","urls":{"html":"https://cve.report/CVE-2010-2480","api":"https://cve.report/api/cve/CVE-2010-2480.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-2480","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-2480"},"summary":{"title":"CVE-2010-2480","description":"Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.","state":"PUBLISHED","assigner":"redhat","published_at":"2010-07-02 19:00:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2010:014","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.makotemplates.org/CHANGES","name":"http://www.makotemplates.org/CHANGES","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39935","name":"http://secunia.com/advisories/39935","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Mako \"cgi.escape()\" Cross-Site Scripting Vulnerability - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.python.org/issue9061","name":"http://bugs.python.org/issue9061","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Issue 9061: cgi.escape Can Lead To XSS Vulnerabilities - Python tracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2010-2480","name":"MISC:https://access.redhat.com/security/cve/CVE-2010-2480","refsource":"MITRE","tags":[],"title":"CVE-2010-2480 - Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=609573","name":"MISC:https://bugzilla.redhat.com/show_bug.cgi?id=609573","refsource":"MITRE","tags":[],"title":"609573 – (CVE-2010-2480) CVE-2010-2480 Python-Mako (prior v0.3.4): Improper escaping of single quotes in escape.cgi (XSS)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-2480","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-2480","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.0","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.1.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.2.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"0.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2480","vulnerable":"1","versionEndIncluding":"0.3.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"makotemplates","cpe5":"mako","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T02:32:16.854Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.makotemplates.org/CHANGES"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://bugs.python.org/issue9061"},{"name":"SUSE-SR:2010:014","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html"},{"name":"39935","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39935"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-06-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-09-09T09:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.makotemplates.org/CHANGES"},{"tags":["x_refsource_MISC"],"url":"http://bugs.python.org/issue9061"},{"name":"SUSE-SR:2010:014","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html"},{"name":"39935","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39935"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2010-2480","datePublished":"2010-07-02T18:30:00.000Z","dateReserved":"2010-06-28T00:00:00.000Z","dateUpdated":"2024-08-07T02:32:16.854Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-07-02 19:00:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:*:*:*:*:*:*:*:*","versionEndIncluding":"0.3.3","matchCriteriaId":"99BA2C41-E26E-402F-881A-364E08D54D9D"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.0:-:*:*:*:*:*:*","matchCriteriaId":"02668582-3F00-4950-A6B7-0300E1E6FEE3"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.1:*:*:*:*:*:*:*","matchCriteriaId":"EF3AC048-0E2C-4F1B-8CB0-9A9B0BBC613A"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.2:*:*:*:*:*:*:*","matchCriteriaId":"0DE88A4A-9326-4121-8F51-7FDAFADA3601"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.3:*:*:*:*:*:*:*","matchCriteriaId":"14F4C349-0F78-47CC-84FB-E7B22212F3B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.4:*:*:*:*:*:*:*","matchCriteriaId":"CF4F91E1-3361-4051-AF32-977A008BFE0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.5:*:*:*:*:*:*:*","matchCriteriaId":"D07E6D43-7F35-40FE-ABBC-1A99D7B2B021"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.6:*:*:*:*:*:*:*","matchCriteriaId":"C53A02BD-C2EB-49DB-B8F3-A6264A076FC3"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.7:*:*:*:*:*:*:*","matchCriteriaId":"5E20E974-04BC-423A-8FB8-FC33E50F8E2C"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.8:*:*:*:*:*:*:*","matchCriteriaId":"87453A9D-2B42-4434-8240-809F4993A85C"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.9:*:*:*:*:*:*:*","matchCriteriaId":"2ED07982-90DB-44CB-931C-79068B204052"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.1.10:*:*:*:*:*:*:*","matchCriteriaId":"7622EA4F-8320-493B-832C-C567BBA705A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.2.0:*:*:*:*:*:*:*","matchCriteriaId":"2DF52184-D881-489B-8ABE-D61F40154E7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.2.1:*:*:*:*:*:*:*","matchCriteriaId":"7BFDED68-3CD4-4708-B2CA-AED5B1DF769F"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.2.2:*:*:*:*:*:*:*","matchCriteriaId":"5BD7CFC9-F7D5-4906-8434-B36433B1EEE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.2.3:*:*:*:*:*:*:*","matchCriteriaId":"3BA53FC7-981A-4662-8A4E-CEC6B50A136E"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.2.4:*:*:*:*:*:*:*","matchCriteriaId":"A8F8F663-B6EA-4261-AB8C-875C72412405"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.2.5:*:*:*:*:*:*:*","matchCriteriaId":"B74BFFE5-477F-4053-86A2-C9B40AFAB779"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.2.6:*:*:*:*:*:*:*","matchCriteriaId":"64FCD94A-E1F5-4E7D-A8E6-FA52851096AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.3:*:*:*:*:*:*:*","matchCriteriaId":"F55E06A3-4B50-4076-836C-FC773C0F7F29"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.3.1:*:*:*:*:*:*:*","matchCriteriaId":"B432586F-E6EF-4028-8CFB-895674661150"},{"vulnerable":true,"criteria":"cpe:2.3:a:makotemplates:mako:0.3.2:*:*:*:*:*:*:*","matchCriteriaId":"E68F133F-B40C-44F8-81CF-68D2B7040A58"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"2480","Ordinal":"1","Title":"CVE-2010-2480","CVE":"CVE-2010-2480","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"2480","Ordinal":"1","NoteData":"Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.","Type":"Description","Title":"CVE-2010-2480"},{"CveYear":"2010","CveId":"2480","Ordinal":"2","NoteData":"2010-07-02","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"2480","Ordinal":"3","NoteData":"2010-09-09","Type":"Other","Title":"Modified"}]}}}