CVE

Id
12844  
CVE No.
CVE-2005-1638  
Status
Candidate  
Description
The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.  
Phase
Assigned (20050517)  
Votes
None (candidate not yet proposed)  
Comments