PT-2020-7447 · Videolan · Vlc Media Player
Published
2013-08-09
·
Updated
2020-02-03
·
CVE-2013-3565
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
VLC Media Player versions prior to 2.0.7
Description:
The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface of VLC Media Player. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the vulnerabilities can be exploited through the
command parameter to requests/vlm cmd.xml, the dir parameter to requests/browse.xml, or the URI in a request, which is returned in an error message through share/lua/intf/http.lua.Recommendations:
For versions prior to 2.0.7, update to version 2.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP Interface or disabling the vulnerable parameters, such as
command and dir, until a patch is applied. Avoid using the vulnerable URI in requests until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vlc Media Player