CVE-2010-4209: XSS
Published Nov 7, 2010
·Updated
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf.
Affected Software
6 affected components
Yahoo YUI=2.8.0
Yahoo YUI=2.8.1
Mozilla Bugzilla=3.7.1
Mozilla Bugzilla=3.7.2
Mozilla Bugzilla=3.7.3
Mozilla Bugzilla=4.1
Remediation
Patch Available
Event History
Nov 7, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
10:00 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-4209?
CVE-2010-4209 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
Which versions are affected by CVE-2010-4209?
CVE-2010-4209 affects Yahoo YUI versions 2.8.0 and 2.8.1.
3
How can I mitigate CVE-2010-4209?
To mitigate CVE-2010-4209, upgrade to a version of Yahoo YUI that is not affected, or implement input validation on user data.
4
What types of attacks can CVE-2010-4209 allow?
CVE-2010-4209 allows remote attackers to inject arbitrary web scripts or HTML into affected applications.
5
Does CVE-2010-4209 affect Bugzilla?
CVE-2010-4209 impacts Bugzilla versions 3.7.1 through 3.7.3 and 4.1.