PT-2014-3210 · Mozilla+1 · Firefox+1
Published
2014-01-26
·
Updated
2021-09-22
·
CVE-2013-6853
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Y! Toolbar plugin for FireFox version 3.1.0.20130813024103 for Mac
Y! Toolbar plugin for FireFox version 2.5.9.2013418100420 for Windows
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL that is stored by the victim. This occurs in the clickstream.js component of the Y! Toolbar plugin for FireFox.
Recommendations
For Y! Toolbar plugin for FireFox version 3.1.0.20130813024103 for Mac, update to a version that fixes the XSS vulnerability in clickstream.js.
For Y! Toolbar plugin for FireFox version 2.5.9.2013418100420 for Windows, update to a version that fixes the XSS vulnerability in clickstream.js.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox
Y! Toolbar Plugin For Firefox