Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-5881

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2012-5881
Last Modified 31 Jan 2013 11:53:10
Published 16 Nov 2012 07:24:24
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-5881

Summary

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.

Vulnerable Systems

Application

  • Yahoo Yui 2.4.0

  • Yahoo Yui 2.4.1

  • Yahoo Yui 2.5.0

  • Yahoo Yui 2.5.1

  • Yahoo Yui 2.5.2

  • Yahoo Yui 2.6.0

  • Yahoo Yui 2.7.0

  • Yahoo Yui 2.8.0

  • Yahoo Yui 2.8.1

  • Yahoo Yui 2.8.2

  • Yahoo Yui 2.9.0


References

CONFIRM - http://yuilibrary.com/support/20121030-vulnerability/

CONFIRM - http://www.yuiblog.com/blog/2012/11/05/post-mortem-swf-vulnerability-in-yui-2/

CONFIRM - http://www.yuiblog.com/blog/2012/10/30/security-announcement-swf-vulnerability-in-yui-2/

XF - yui-flash-component-xss(80118)


Last Updated: 27 May 2016 10:58:28