Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2021-35043
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.003
EPSS Ranking
55.3%
CVSS Severity
CVSS v3 Score
6.1
CVSS v2 Score
4.3
References
https://github.com/nahsra/antisamy/pull/87
https://github.com/nahsra/antisamy/releases/tag/v1.6.4
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://github.com/nahsra/antisamy/pull/87
https://github.com/nahsra/antisamy/releases/tag/v1.6.4
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html
Products affected by CVE-2021-35043
Antisamy Project
»
Antisamy
»
Version:
N/A
cpe:2.3:a:antisamy_project:antisamy:-
Antisamy Project
»
Antisamy
»
Version:
1.4.1
cpe:2.3:a:antisamy_project:antisamy:1.4.1
Antisamy Project
»
Antisamy
»
Version:
1.4.2
cpe:2.3:a:antisamy_project:antisamy:1.4.2
Antisamy Project
»
Antisamy
»
Version:
1.4.3
cpe:2.3:a:antisamy_project:antisamy:1.4.3
Antisamy Project
»
Antisamy
»
Version:
1.4.4
cpe:2.3:a:antisamy_project:antisamy:1.4.4
Antisamy Project
»
Antisamy
»
Version:
1.4.5
cpe:2.3:a:antisamy_project:antisamy:1.4.5
Antisamy Project
»
Antisamy
»
Version:
1.5
cpe:2.3:a:antisamy_project:antisamy:1.5
Antisamy Project
»
Antisamy
»
Version:
1.5.1
cpe:2.3:a:antisamy_project:antisamy:1.5.1
Antisamy Project
»
Antisamy
»
Version:
1.5.10
cpe:2.3:a:antisamy_project:antisamy:1.5.10
Antisamy Project
»
Antisamy
»
Version:
1.5.11
cpe:2.3:a:antisamy_project:antisamy:1.5.11
Antisamy Project
»
Antisamy
»
Version:
1.5.12
cpe:2.3:a:antisamy_project:antisamy:1.5.12
Antisamy Project
»
Antisamy
»
Version:
1.5.13
cpe:2.3:a:antisamy_project:antisamy:1.5.13
Antisamy Project
»
Antisamy
»
Version:
1.5.2
cpe:2.3:a:antisamy_project:antisamy:1.5.2
Antisamy Project
»
Antisamy
»
Version:
1.5.3
cpe:2.3:a:antisamy_project:antisamy:1.5.3
Antisamy Project
»
Antisamy
»
Version:
1.5.5
cpe:2.3:a:antisamy_project:antisamy:1.5.5
Antisamy Project
»
Antisamy
»
Version:
1.5.6
cpe:2.3:a:antisamy_project:antisamy:1.5.6
Antisamy Project
»
Antisamy
»
Version:
1.5.7
cpe:2.3:a:antisamy_project:antisamy:1.5.7
Antisamy Project
»
Antisamy
»
Version:
1.5.8
cpe:2.3:a:antisamy_project:antisamy:1.5.8
Antisamy Project
»
Antisamy
»
Version:
1.5.9
cpe:2.3:a:antisamy_project:antisamy:1.5.9
Antisamy Project
»
Antisamy
»
Version:
1.6.0
cpe:2.3:a:antisamy_project:antisamy:1.6.0
Antisamy Project
»
Antisamy
»
Version:
1.6.1
cpe:2.3:a:antisamy_project:antisamy:1.6.1
Antisamy Project
»
Antisamy
»
Version:
1.6.2
cpe:2.3:a:antisamy_project:antisamy:1.6.2
Antisamy Project
»
Antisamy
»
Version:
1.6.3
cpe:2.3:a:antisamy_project:antisamy:1.6.3
Netapp
»
Active Iq Unified Manager
»
Version:
N/A
cpe:2.3:a:netapp:active_iq_unified_manager:-
Oracle
»
Banking Enterprise Default Management
»
Version:
2.10.0
cpe:2.3:a:oracle:banking_enterprise_default_management:2.10.0
Oracle
»
Banking Enterprise Default Management
»
Version:
2.12.0
cpe:2.3:a:oracle:banking_enterprise_default_management:2.12.0
Oracle
»
Banking Enterprise Default Management
»
Version:
2.6.2
cpe:2.3:a:oracle:banking_enterprise_default_management:2.6.2
Oracle
»
Banking Enterprise Default Management
»
Version:
2.7.0
cpe:2.3:a:oracle:banking_enterprise_default_management:2.7.0
Oracle
»
Banking Enterprise Default Management
»
Version:
2.7.1
cpe:2.3:a:oracle:banking_enterprise_default_management:2.7.1
Oracle
»
Banking Enterprise Default Managment
»
Version:
Any
cpe:2.3:a:oracle:banking_enterprise_default_managment:*
Oracle
»
Banking Party Management
»
Version:
2.7.0
cpe:2.3:a:oracle:banking_party_management:2.7.0
Oracle
»
Banking Platform
»
Version:
2.3.0
cpe:2.3:a:oracle:banking_platform:2.3.0
Oracle
»
Banking Platform
»
Version:
2.4.0
cpe:2.3:a:oracle:banking_platform:2.4.0
Oracle
»
Banking Platform
»
Version:
2.4.1
cpe:2.3:a:oracle:banking_platform:2.4.1
Oracle
»
Banking Platform
»
Version:
2.6.2
cpe:2.3:a:oracle:banking_platform:2.6.2
Oracle
»
Banking Platform
»
Version:
2.7.0
cpe:2.3:a:oracle:banking_platform:2.7.0
Oracle
»
Banking Platform
»
Version:
2.7.1
cpe:2.3:a:oracle:banking_platform:2.7.1
Oracle
»
Insurance Policy Administration
»
Version:
11.0.2
cpe:2.3:a:oracle:insurance_policy_administration:11.0.2
Oracle
»
Insurance Policy Administration
»
Version:
11.1.0
cpe:2.3:a:oracle:insurance_policy_administration:11.1.0
Oracle
»
Insurance Policy Administration
»
Version:
11.2.8
cpe:2.3:a:oracle:insurance_policy_administration:11.2.8
Oracle
»
Insurance Policy Administration
»
Version:
11.3.0
cpe:2.3:a:oracle:insurance_policy_administration:11.3.0
Oracle
»
Insurance Policy Administration
»
Version:
11.3.1
cpe:2.3:a:oracle:insurance_policy_administration:11.3.1
Oracle
»
Middleware Common Libraries And Tools
»
Version:
12.2.1.3.0
cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.3.0
Oracle
»
Middleware Common Libraries And Tools
»
Version:
12.2.1.4.0
cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0
Oracle
»
Retail Back Office
»
Version:
14.0
cpe:2.3:a:oracle:retail_back_office:14.0
Oracle
»
Retail Back Office
»
Version:
14.1
cpe:2.3:a:oracle:retail_back_office:14.1
Oracle
»
Retail Central Office
»
Version:
14.0
cpe:2.3:a:oracle:retail_central_office:14.0
Oracle
»
Retail Central Office
»
Version:
14.1
cpe:2.3:a:oracle:retail_central_office:14.1
Oracle
»
Retail Returns Management
»
Version:
14.0
cpe:2.3:a:oracle:retail_returns_management:14.0
Oracle
»
Retail Returns Management
»
Version:
14.1
cpe:2.3:a:oracle:retail_returns_management:14.1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved