CVE-2012-1647: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the "stand alone PHP application for the OSM Player," as used in the MediaFront module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal, allow remote attackers to inject arbitrary web script or HTML via (1) $SERVER['HTTPHOST'] or (2) $SERVER['SCRIPTNAME'] to players/osmplayer/player/OSMPlayer.php, (3) playlist parameter to players/osmplayer/player/getplaylist.php, and possibly other vectors related to $SESSION.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1647?
CVE-2012-1647 has a medium severity rating due to its ability to allow remote attackers to exploit cross-site scripting vulnerabilities.
How do I fix CVE-2012-1647?
To fix CVE-2012-1647, you should upgrade to MediaFront version 6.x-1.5 or 7.x-1.5 or later.
What types of vulnerabilities are described in CVE-2012-1647?
CVE-2012-1647 describes multiple cross-site scripting (XSS) vulnerabilities.
Which versions of MediaFront are affected by CVE-2012-1647?
MediaFront versions 6.x-1.0 through 6.x-1.4 and 7.x-1.0 through 7.x-1.4 are affected by CVE-2012-1647.
Can CVE-2012-1647 be exploited remotely?
Yes, CVE-2012-1647 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.