First published: Fri Nov 16 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader.swf, a similar issue to CVE-2010-4208.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Yui | =2.4.0 | |
Yahoo Yui | =2.4.1 | |
Yahoo Yui | =2.5.0 | |
Yahoo Yui | =2.5.1 | |
Yahoo Yui | =2.5.2 | |
Yahoo Yui | =2.6.0 | |
Yahoo Yui | =2.7.0 | |
Yahoo Yui | =2.8.0 | |
Yahoo Yui | =2.8.1 | |
Yahoo Yui | =2.8.1-pr1 | |
Yahoo Yui | =2.8.2 | |
Yahoo Yui | =2.9.0 | |
Yahoo Yui | =2.9.0-pr2 | |
Yahoo Yui | =2.9.0-pr4 | |
<=10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2012-5882.
The severity of CVE-2012-5882 is medium with a score of 4.3.
Cross-site scripting (XSS) vulnerability is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
The affected software for CVE-2012-5882 is the YUI library versions 2.4.0 through 2.9.0.
To fix the CVE-2012-5882 vulnerability, you should update the YUI library to a version that is not affected by the vulnerability.