First published: Sun Nov 07 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Yui | =2.8.0 | |
Yahoo Yui | =2.8.1 | |
Mozilla Bugzilla | =3.7.1 | |
Mozilla Bugzilla | =3.7.2 | |
Mozilla Bugzilla | =3.7.3 | |
Mozilla Bugzilla | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4209 is classified as a high severity cross-site scripting (XSS) vulnerability.
CVE-2010-4209 affects Yahoo YUI versions 2.8.0 and 2.8.1.
To mitigate CVE-2010-4209, upgrade to a version of Yahoo YUI that is not affected, or implement input validation on user data.
CVE-2010-4209 allows remote attackers to inject arbitrary web scripts or HTML into affected applications.
CVE-2010-4209 impacts Bugzilla versions 3.7.1 through 3.7.3 and 4.1.