Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjg9-mf63-vqrp

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Cross-site scripting in yui 2.4.0

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.

Пакеты

Наименование

yui2

npm
Затронутые версииВерсия исправления

>= 2.4.0, <= 2.9.0

Отсутствует

EPSS

Процентиль: 49%
0.00256
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 13 лет назад

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.

nvd
около 13 лет назад

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.

debian
около 13 лет назад

Cross-site scripting (XSS) vulnerability in the Flash component infras ...

EPSS

Процентиль: 49%
0.00256
Низкий

Дефекты

CWE-79