PT-2010-5357 · Yahoo+1 · Yui+1
Publicado
2010-11-07
·
Atualizado
2011-02-05
·
CVE-2010-4209
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
YUI versions 2.8.0 through 2.8.1
Bugzilla versions 3.7.1 through 3.7.3
Bugzilla version 4.1
Description
A cross-site scripting (XSS) issue exists in the Flash component infrastructure in YUI, as used in Bugzilla, allowing remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf.
Recommendations
For YUI versions 2.8.0 through 2.8.1, consider disabling the Flash component infrastructure until a patch is available.
For Bugzilla versions 3.7.1 through 3.7.3, restrict access to the Flash component infrastructure to minimize the risk of exploitation.
For Bugzilla version 4.1, avoid using the Flash component infrastructure in the affected versions until the issue is resolved.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bugzilla
Yui