CVE-2010-2477
Publication date 5 November 2010
Last updated 24 July 2024
Ubuntu priority
Description
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| paste | ||
Patch details
| Package | Patch details | 
|---|---|
| paste | 
References
Related Ubuntu Security Notices (USN)
- USN-1026-1
 - Python Paste vulnerability
 - 7 December 2010