mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 15:08:03 +02:00
18 lines
707 B
Markdown
18 lines
707 B
Markdown
### [CVE-2014-2966](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2966)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://www.kb.cert.org/vuls/id/162308
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|