CVE-2010-2274

Source
https://nvd.nist.gov/vuln/detail/CVE-2010-2274
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2010-2274.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2010-2274
Aliases
Published
2010-06-15T14:30:01Z
Modified
2025-04-11T00:51:21Z
Summary
[none]
Details

Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.

References

Affected packages

Debian:11 / dojo

Package

Name
dojo
Purl
pkg:deb/debian/dojo?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.2+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / dojo

Package

Name
dojo
Purl
pkg:deb/debian/dojo?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.2+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / dojo

Package

Name
dojo
Purl
pkg:deb/debian/dojo?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.2+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}