First published: Wed Feb 05 2014(Updated: )
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mediaelementjs Mediaelement.js | <=2.11.1 | |
Mediaelementjs Mediaelement.js | =1.0.0 | |
Mediaelementjs Mediaelement.js | =1.0.1 | |
Mediaelementjs Mediaelement.js | =1.0.2 | |
Mediaelementjs Mediaelement.js | =1.0.3 | |
Mediaelementjs Mediaelement.js | =1.0.4 | |
Mediaelementjs Mediaelement.js | =1.0.5 | |
Mediaelementjs Mediaelement.js | =1.0.6 | |
Mediaelementjs Mediaelement.js | =1.0.7 | |
Mediaelementjs Mediaelement.js | =1.1.0 | |
Mediaelementjs Mediaelement.js | =1.1.1 | |
Mediaelementjs Mediaelement.js | =1.1.2 | |
Mediaelementjs Mediaelement.js | =1.1.3 | |
Mediaelementjs Mediaelement.js | =1.1.4 | |
Mediaelementjs Mediaelement.js | =1.1.5 | |
Mediaelementjs Mediaelement.js | =1.1.6 | |
Mediaelementjs Mediaelement.js | =1.1.7 | |
Mediaelementjs Mediaelement.js | =2.0.0 | |
Mediaelementjs Mediaelement.js | =2.0.1 | |
Mediaelementjs Mediaelement.js | =2.0.2 | |
Mediaelementjs Mediaelement.js | =2.0.3 | |
Mediaelementjs Mediaelement.js | =2.0.4 | |
Mediaelementjs Mediaelement.js | =2.0.5 | |
Mediaelementjs Mediaelement.js | =2.0.6 | |
Mediaelementjs Mediaelement.js | =2.0.7 | |
Mediaelementjs Mediaelement.js | =2.1.0 | |
Mediaelementjs Mediaelement.js | =2.1.1 | |
Mediaelementjs Mediaelement.js | =2.1.2 | |
Mediaelementjs Mediaelement.js | =2.1.3 | |
Mediaelementjs Mediaelement.js | =2.1.4 | |
Mediaelementjs Mediaelement.js | =2.1.5 | |
Mediaelementjs Mediaelement.js | =2.1.6 | |
Mediaelementjs Mediaelement.js | =2.1.7 | |
Mediaelementjs Mediaelement.js | =2.1.8 | |
Mediaelementjs Mediaelement.js | =2.1.9 | |
Mediaelementjs Mediaelement.js | =2.2.0 | |
Mediaelementjs Mediaelement.js | =2.2.1 | |
Mediaelementjs Mediaelement.js | =2.2.2 | |
Mediaelementjs Mediaelement.js | =2.2.3 | |
Mediaelementjs Mediaelement.js | =2.2.4 | |
Mediaelementjs Mediaelement.js | =2.2.5 | |
Mediaelementjs Mediaelement.js | =2.3.0 | |
Mediaelementjs Mediaelement.js | =2.3.1 | |
Mediaelementjs Mediaelement.js | =2.3.2 | |
Mediaelementjs Mediaelement.js | =2.3.3 | |
Mediaelementjs Mediaelement.js | =2.4.0 | |
Mediaelementjs Mediaelement.js | =2.4.1 | |
Mediaelementjs Mediaelement.js | =2.4.2 | |
Mediaelementjs Mediaelement.js | =2.4.3 | |
Mediaelementjs Mediaelement.js | =2.5.0 | |
Mediaelementjs Mediaelement.js | =2.6.0 | |
Mediaelementjs Mediaelement.js | =2.6.1 | |
Mediaelementjs Mediaelement.js | =2.6.2 | |
Mediaelementjs Mediaelement.js | =2.6.3 | |
Mediaelementjs Mediaelement.js | =2.6.4 | |
Mediaelementjs Mediaelement.js | =2.6.5 | |
Mediaelementjs Mediaelement.js | =2.7.0 | |
Mediaelementjs Mediaelement.js | =2.8.0 | |
Mediaelementjs Mediaelement.js | =2.8.1 | |
Mediaelementjs Mediaelement.js | =2.8.2 | |
Mediaelementjs Mediaelement.js | =2.9.0 | |
Mediaelementjs Mediaelement.js | =2.9.1 | |
Mediaelementjs Mediaelement.js | =2.9.2 | |
Mediaelementjs Mediaelement.js | =2.9.3 | |
Mediaelementjs Mediaelement.js | =2.9.4 | |
Mediaelementjs Mediaelement.js | =2.9.5 | |
Mediaelementjs Mediaelement.js | =2.10.0 | |
Mediaelementjs Mediaelement.js | =2.10.1 | |
Mediaelementjs Mediaelement.js | =2.10.2 | |
Mediaelementjs Mediaelement.js | =2.10.3 | |
Mediaelementjs Mediaelement.js | =2.11.0 | |
ownCloud Desktop Client | =4.5.0 | |
ownCloud Desktop Client | =4.5.1 | |
ownCloud Desktop Client | =4.5.2 | |
ownCloud Desktop Client | =4.5.3 | |
ownCloud Desktop Client | =4.5.4 | |
ownCloud Desktop Client | =4.5.5 | |
ownCloud Desktop Client | =4.5.6 | |
ownCloud Desktop Client | =4.5.7 | |
ownCloud Desktop Client | =4.5.8 | |
ownCloud Desktop Client | =4.5.9 | |
ownCloud Desktop Client | =5.0.0 | |
ownCloud Desktop Client | =5.0.1 | |
ownCloud Desktop Client | =5.0.2 | |
ownCloud Desktop Client | =5.0.3 | |
ownCloud Desktop Client | =5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1967 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2013-1967, update MediaElement.js to version 2.11.2 or later, or upgrade ownCloud to version 5.0.5 or later.
CVE-2013-1967 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
MediaElement.js versions prior to 2.11.2, including 2.10.x and earlier, are affected by CVE-2013-1967.
CVE-2013-1967 impacts ownCloud Server versions 4.5.0 to 4.5.9 and 5.0.0 to 5.0.4 before the patches were applied.