Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.
We have discovered 356,530 live websites that are affected by CVE-2012-6662.
Product | |
Category | JavaScript Libraries |
Vulnerable Domains | 356,530 live websites (7.24% of jQuery UI install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 65 versions ( 56.03% of all versions) |
![]() | 114,460 websites |
![]() | 33,325 websites |
![]() | 22,402 websites |
![]() | 21,865 websites |
![]() | 11,705 websites |
![]() | 11,432 websites |
![]() | 11,328 websites |
![]() | 10,978 websites |
![]() | 10,785 websites |
![]() | 7,151 websites |
.com | 139,370 websites |
.ru | 19,272 websites |
.de | 18,949 websites |
.org | 14,001 websites |
.net | 11,360 websites |
.pl | 9,918 websites |
.cz | 9,910 websites |
.nl | 9,477 websites |
.fr | 8,549 websites |
.co.uk | 7,871 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.com | ![]() | *,*** | |
*********************.de | ![]() | *,*** | |
******.***.***.cn | ![]() | *,*** | |
****.***********.pl | ![]() | *,*** | |
*******.org | ![]() | *,*** | |
************.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
***.int | ![]() | *,*** | |
*********.de | ![]() | *,*** | |
********.com | ![]() | *,*** |
FAQ