Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-6780

Опубликовано: 13 нояб. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
esm-infra/xenial

not-affected

lucid

DNE

precise

not-affected

precise/esm

DNE

precise was not-affected
quantal

not-affected

raring

not-affected

saucy

not-affected

trusty

not-affected

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
lucid

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

not-affected

raring

not-affected

saucy

not-affected

trusty

not-affected

Показывать по

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
esm-infra/xenial

not-affected

lucid

DNE

precise

DNE

precise/esm

DNE

quantal

not-affected

raring

not-affected

saucy

not-affected

trusty

not-affected

Показывать по

EPSS

Процентиль: 73%
0.00777
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 12 лет назад

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.

nvd
около 12 лет назад

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.

debian
около 12 лет назад

Cross-site scripting (XSS) vulnerability in uploader.swf in the Upload ...

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.

EPSS

Процентиль: 73%
0.00777
Низкий

4.3 Medium

CVSS2