CVE-2013-1808: XSS
Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the same vulnerability as CVE-2013-1463. If so, it is likely that CVE-2013-1463 will be REJECTed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1808?
The severity of CVE-2013-1808 is considered medium due to its potential for exploitation via cross-site scripting attacks.
How do I fix CVE-2013-1808?
To fix CVE-2013-1808, upgrade to ZeroClipboard version 1.0.8 or later.
What types of applications are affected by CVE-2013-1808?
CVE-2013-1808 affects various applications that utilize ZeroClipboard, including em-shorty, RepRapCalculator, Fulcrum, Django, and aCMS.
What can attackers do with CVE-2013-1808?
Attackers can exploit CVE-2013-1808 to inject arbitrary web scripts or HTML via the id parameter.
Is ZeroClipboard the only software affected by CVE-2013-1808?
While ZeroClipboard is the primary software affected by CVE-2013-1808, it is used within multiple other applications, making those also susceptible.