Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a "\" (backslash) within a "javascript" scheme in a style property (such as "javas\cript"), which bypasses the "javascript" check before the "\" is stripped and then rendered in web browsers that allow scripting in style sheets.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T23:46:05.093Z
Reserved: 2005-12-21T00:00:00
Link: CVE-2005-4454

No data.

Status : Deferred
Published: 2005-12-21T11:03:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-4454

No data.