CVE-2011-1221: XSS
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document, a different vulnerability than CVE-2011-2947.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1221?
CVE-2011-1221 is classified as a moderate severity vulnerability due to its potential for cross-zone scripting attacks.
How do I fix CVE-2011-1221?
To fix CVE-2011-1221, users should update their RealPlayer software to the latest version that addresses this vulnerability.
Which versions of RealPlayer are affected by CVE-2011-1221?
CVE-2011-1221 affects RealPlayer versions 11.0 through 11.1, and 14.0.0 through 14.0.5, as well as RealPlayer SP 1.0 through 1.1.5.
What type of vulnerability is CVE-2011-1221?
CVE-2011-1221 is a cross-zone scripting vulnerability that allows remote attackers to inject arbitrary web script or HTML.
What impact could CVE-2011-1221 have on users?
If exploited, CVE-2011-1221 could allow attackers to execute malicious scripts in the context of a user's browser.