CVE-2011-2947: XSS
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2947?
CVE-2011-2947 is considered a moderate severity vulnerability due to its potential for cross-zone scripting attacks.
How do I fix CVE-2011-2947?
To fix CVE-2011-2947, update your RealPlayer software to the latest version provided by RealNetworks.
Which versions of RealPlayer are affected by CVE-2011-2947?
CVE-2011-2947 affects RealPlayer versions 11.0, 11.1, and 14.0.0 through 14.0.5 as well as RealPlayer SP versions 1.0 through 1.1.5.
Can CVE-2011-2947 be exploited remotely?
Yes, CVE-2011-2947 can be exploited remotely via a local HTML document that injects arbitrary web script or HTML.
What is the nature of the vulnerability in CVE-2011-2947?
CVE-2011-2947 is a cross-zone scripting vulnerability that allows attackers to inject malicious scripts into the Local Zone.