Demand Media · Pluck Sitelife · CVE-2012-0253
**Name of the Vulnerable Software and Affected Versions**
Demand Media Pluck SiteLife versions prior to 5.0.13
**Description**
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via several parameters, including the `jsonRequest` parameter to "Direct/Process", the `r` or `cb` parameter to "Direct/jsonp.htm", or the `cb` parameter to "sys/jsonp.app/.htm".
**Recommendations**
For versions prior to 5.0.13, update to version 5.0.13 or later to resolve the issue.