4.3
CVSSv2

CVE-2014-3146

Published: 14/05/2014 Updated: 29/12/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Incomplete blacklist vulnerability in the lxml.html.clean module in lxml prior to 3.3.5 allows remote malicious users to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lxml lxml

lxml lxml 3.3.0

lxml lxml 3.2.0

lxml lxml 3.1.2

lxml lxml 3.0

lxml lxml 2.3

lxml lxml 2.2.4

lxml lxml 2.2.3

lxml lxml 2.2.2

lxml lxml 2.1.4

lxml lxml 2.0.11

lxml lxml 2.0.8

lxml lxml 2.1

lxml lxml 2.0.2

lxml lxml 2.0.1

lxml lxml 1.3.2

lxml lxml 1.3.1

lxml lxml 1.0.4

lxml lxml 1.0.3

lxml lxml 0.7

lxml lxml 0.6

lxml lxml 3.3.1

lxml lxml 3.2.4

lxml lxml 3.2.3

lxml lxml 3.0.2

lxml lxml 3.0.1

lxml lxml 2.3.4

lxml lxml 2.3.3

lxml lxml 2.2.8

lxml lxml 2.2.7

lxml lxml 2.2

lxml lxml 2.0.10

lxml lxml 2.1.2

lxml lxml 2.0.6

lxml lxml 1.3.6

lxml lxml 1.3.5

lxml lxml 1.2

lxml lxml 1.1.2

lxml lxml 1.0

lxml lxml 0.9.2

lxml lxml 0.9.1

lxml lxml 3.3.3

lxml lxml 3.3.2

lxml lxml 3.2.5

lxml lxml 3.1.1

lxml lxml 3.1.0

lxml lxml 3.1

lxml lxml 2.3.6

lxml lxml 2.3.5

lxml lxml 2.2.1

lxml lxml 2.1.3

lxml lxml 2.0.7

lxml lxml 2.0

lxml lxml 1.3

lxml lxml 1.2.1

lxml lxml 1.0.2

lxml lxml 1.0.1

lxml lxml 0.5.1

lxml lxml 0.5

lxml lxml 3.2.2

lxml lxml 3.2.1

lxml lxml 2.3.2

lxml lxml 2.3.1

lxml lxml 2.2.6

lxml lxml 2.2.5

lxml lxml 2.0.9

lxml lxml 2.1.1

lxml lxml 2.0.5

lxml lxml 2.0.4

lxml lxml 2.0.3

lxml lxml 1.3.4

lxml lxml 1.3.3

lxml lxml 1.1.1

lxml lxml 1.1

lxml lxml 0.9

lxml lxml 0.8

Vendor Advisories

Debian Bug report logs - #746812 python-lxml: CVE-2014-3146: clean_html input sanitization flaw Package: src:lxml; Maintainer for src:lxml is Matthias Klose <doko@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 3 May 2014 21:24:02 UTC Severity: important Tags: fixed-upstream, security, ...
lxml could allow cross-site scripting (XSS) attacks ...
Incomplete blacklist vulnerability in the lxmlhtmlclean module in lxml before 335 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function ...

Exploits

source: wwwsecurityfocuscom/bid/67159/info lxml is prone to a security-bypass vulnerability An attacker can leverage this issue to bypass security restrictions and perform unauthorized actions This may aid in further attacks Versions prior to lxml 335 are vulnerable from lxmlhtmlclean import clean_html html = '''\ <html&gt ...