4.3
CVSSv2

CVE-2011-1158

Published: 11/04/2011 Updated: 24/08/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x prior to 5.0.1 allows remote malicious users to inject arbitrary web script or HTML via an unexpected URI scheme, as demonstrated by a javascript: URI.

Vulnerable Product Search on Vulmon Subscribe to Product

mark pilgrim feedparser 5.0

Vendor Advisories

Debian Bug report logs - #617998 python-feedparser: please update feedparser, it hasn't been updated in a _long_ time Package: python-feedparser; Maintainer for python-feedparser is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Source for python-feedparser is src:feedparser (PTS, buildd, popcon) R ...