First published: Fri Nov 16 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Yui | =2.4.0 | |
Yahoo Yui | =2.4.1 | |
Yahoo Yui | =2.5.0 | |
Yahoo Yui | =2.5.1 | |
Yahoo Yui | =2.5.2 | |
Yahoo Yui | =2.6.0 | |
Yahoo Yui | =2.7.0 | |
Yahoo Yui | =2.8.0 | |
Yahoo Yui | =2.8.1 | |
Yahoo Yui | =2.8.1-pr1 | |
Yahoo Yui | =2.8.2 | |
Yahoo Yui | =2.9.0 | |
Yahoo Yui | =2.9.0-pr2 | |
Yahoo Yui | =2.9.0-pr4 | |
<=10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this YUI library vulnerability is CVE-2012-5881.
The severity of CVE-2012-5881 is medium with a severity value of 4.3.
The YUI library versions 2.4.0 to 2.9.0 are affected by CVE-2012-5881.
CVE-2012-5881 is a cross-site scripting (XSS) vulnerability caused by improper validation of user-supplied input by the Flash component infrastructure in the YUI library.
Yes, here are some references for CVE-2012-5881: [link1](http://www.securityfocus.com/bid/56385), [link2](http://www.yuiblog.com/blog/2012/10/30/security-announcement-swf-vulnerability-in-yui-2/), [link3](http://www.yuiblog.com/blog/2012/11/05/post-mortem-swf-vulnerability-in-yui-2/).