First published: Sun Nov 07 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Yui | =2.4.0 | |
Yahoo Yui | =2.5.0 | |
Yahoo Yui | =2.5.1 | |
Yahoo Yui | =2.5.2 | |
Yahoo Yui | =2.6.0 | |
Yahoo Yui | =2.7.0 | |
Yahoo Yui | =2.8.0 | |
Yahoo Yui | =2.8.1 | |
Moodle | ||
Mozilla Bugzilla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4207 is classified as a high severity cross-site scripting (XSS) vulnerability.
To fix CVE-2010-4207, you should upgrade to a version of YUI above 2.8.1 that has addressed the vulnerability.
CVE-2010-4207 affects YUI versions 2.4.0 through 2.8.1.
CVE-2010-4207 can allow remote attackers to inject arbitrary web scripts or HTML into affected applications.
Yes, CVE-2010-4207 can affect applications using YUI, such as Bugzilla and Moodle, if they utilize the vulnerable versions.