Cross-site Scripting (XSS) The advisory has been revoked - it doesn't affect any version of package zonecheck  (opens in a new tab)


Threat Intelligence

EPSS
0.28% (69th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UBUNTU1210-ZONECHECK-667108
  • published10 Sept 2020
  • disclosed3 Jun 2010

Introduced: 3 Jun 2010

CVE-2010-2155  (opens in a new tab)
CWE-79  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:12.10.

NVD Description

Note: Versions mentioned in the description apply only to the upstream zonecheck package and not the zonecheck package as distributed by Ubuntu.

Multiple cross-site scripting (XSS) vulnerabilities in zc/publisher/html.rb in ZoneCheck 2.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) xmlnode.value, (2) zc-error text, (3) $zc_version, (4) domainname in a zc-title row, different vulnerabilities than CVE-2009-4882.