id: PYSEC-2014-99 details: Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page. affected: - package: name: ajenti ecosystem: PyPI purl: pkg:pypi/ajenti ranges: - type: GIT repo: https://github.com/Eugeny/ajenti events: - introduced: "0" - fixed: d3fc5eb142ff16d55d158afb050af18d5ff09120 - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.2.21.7 versions: - 0.99.11 - 0.99.19 - 0.99.20 - 0.99.21 - 0.99.22 - 0.99.23 - 0.99.24 - 0.99.25 - 0.99.26 - 0.99.27 - 0.99.28 - 0.99.29 - 0.99.30 - 0.99.31 - 0.99.32 - 0.99.33 - 0.99.34 - 0.99.35 - 0.99.36 - 0.99.37 - 0.99.38 - 0.99.39 - 0.99.7 - 0.99.8 - 1.0.0 - 1.0.1 - 1.0.2 - 1.0.3 - 1.0.8 - 1.1.0 - 1.1.1 - 1.1.2 - 1.1.3 - 1.1.4 - 1.1.5 - 1.1.6 - 1.1.8 - 1.1.8.2 - 1.1.9 - 1.1.9.1 - 1.1.9.2 - 1.1.9.3 - 1.2.0 - 1.2.1 - 1.2.10 - 1.2.11 - 1.2.11.1 - 1.2.11.2 - 1.2.13 - 1.2.13.1 - 1.2.13.2 - 1.2.14 - 1.2.14.1 - 1.2.15 - 1.2.15.1 - 1.2.16 - 1.2.16.1 - 1.2.16.2 - 1.2.17 - 1.2.17.1 - 1.2.17.2 - 1.2.18 - 1.2.18.2 - 1.2.18.4 - 1.2.18.5 - 1.2.18.6 - 1.2.19.0 - 1.2.19.1 - 1.2.19.2 - 1.2.19.3 - 1.2.19.4 - 1.2.19.5 - 1.2.19.6 - 1.2.19.7 - 1.2.19.8 - 1.2.2 - 1.2.20.0 - 1.2.20.1 - 1.2.20.10 - 1.2.20.2 - 1.2.20.3 - 1.2.20.4 - 1.2.20.5 - 1.2.20.6 - 1.2.20.7 - 1.2.20.8 - 1.2.20.9 - 1.2.21.0 - 1.2.21.1 - 1.2.21.2 - 1.2.21.3 - 1.2.21.4 - 1.2.21.5 - 1.2.21.6 - 1.2.3 - 1.2.4 - 1.2.5 - 1.2.6 - 1.2.6.1 - 1.2.6.2 - 1.2.7 - 1.2.8 - 1.2.9 references: - type: FIX url: https://github.com/Eugeny/ajenti/commit/d3fc5eb142ff16d55d158afb050af18d5ff09120 - type: ADVISORY url: http://secunia.com/advisories/59177 - type: WEB url: https://www.netsparker.com/critical-xss-vulnerabilities-in-ajenti - type: WEB url: http://www.securityfocus.com/bid/68047 - type: ADVISORY url: https://github.com/advisories/GHSA-2ch8-f849-pjg3 aliases: - CVE-2014-4301 - GHSA-2ch8-f849-pjg3 modified: "2021-12-13T06:35:03.086455Z" published: "2014-06-18T14:55:00Z"