First published: Wed Nov 13 2013(Updated: )
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Yui | =2.5.0 | |
Yahoo Yui | =2.5.1 | |
Yahoo Yui | =2.5.2 | |
Yahoo Yui | =2.6.0 | |
Yahoo Yui | =2.7.0 | |
Yahoo Yui | =2.8.0 | |
Yahoo Yui | =2.8.1 | |
Yahoo Yui | =2.8.2 | |
Yahoo Yui | =2.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-6780 is considered high due to the potential for remote cross-site scripting attacks.
To fix CVE-2013-6780, upgrade to a version of Yahoo! YUI that is above 2.9.0.
CVE-2013-6780 can facilitate cross-site scripting (XSS) attacks that allow an attacker to inject arbitrary web scripts.
CVE-2013-6780 affects Yahoo! YUI versions 2.5.0 through 2.9.0.
Mitigation options for CVE-2013-6780 may be limited and the best practice is to upgrade to a fixed version.