PT-2010-5357 · Yahoo+1 · Yui+1

Publicado

2010-11-07

·

Atualizado

2011-02-05

·

CVE-2010-4209

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions YUI versions 2.8.0 through 2.8.1 Bugzilla versions 3.7.1 through 3.7.3 Bugzilla version 4.1
Description A cross-site scripting (XSS) issue exists in the Flash component infrastructure in YUI, as used in Bugzilla, allowing remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf.
Recommendations For YUI versions 2.8.0 through 2.8.1, consider disabling the Flash component infrastructure until a patch is available. For Bugzilla versions 3.7.1 through 3.7.3, restrict access to the Flash component infrastructure to minimize the risk of exploitation. For Bugzilla version 4.1, avoid using the Flash component infrastructure in the affected versions until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-4209

Produtos afetados

Bugzilla
Yui