CVE-2012-5882: XSS
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader.swf, a similar issue to CVE-2010-4208.
Other sources
The YUI library is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the Flash component infrastructure. A remote attacker could exploit this vulnerability using attack vectors related to uploader.swf to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2012-5882.
What is the severity of CVE-2012-5882?
The severity of CVE-2012-5882 is medium with a score of 4.3.
What is cross-site scripting (XSS) vulnerability?
Cross-site scripting (XSS) vulnerability is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
What is the affected software for CVE-2012-5882?
The affected software for CVE-2012-5882 is the YUI library versions 2.4.0 through 2.9.0.
How can I fix the CVE-2012-5882 vulnerability?
To fix the CVE-2012-5882 vulnerability, you should update the YUI library to a version that is not affected by the vulnerability.