First published: Sun Nov 07 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/assets/uploader.swf.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Yui | =2.5.0 | |
Yahoo Yui | =2.5.1 | |
Yahoo Yui | =2.5.2 | |
Yahoo Yui | =2.6.0 | |
Yahoo Yui | =2.7.0 | |
Yahoo Yui | =2.8.0 | |
Yahoo Yui | =2.8.1 | |
Moodle | ||
Mozilla Bugzilla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4208 is considered a high-severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2010-4208, upgrade YUI to version 2.8.2 or later to ensure the XSS vulnerability has been patched.
CVE-2010-4208 affects YUI versions 2.5.0 through 2.8.1 and is utilized in applications like Bugzilla and Moodle.
Cross-site scripting in CVE-2010-4208 refers to the vulnerability that allows remote attackers to inject malicious web scripts into web applications.
To verify if you are vulnerable to CVE-2010-4208, check if you are using YUI versions from 2.5.0 to 2.8.1.