Логотип exploitDog
bind:CVE-2013-2022
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2013-2022

Количество 4

Количество 4

ubuntu логотип

CVE-2013-2022

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.23 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by using the alert function in the jQuery parameter. NOTE: these are the same parameters as CVE-2013-1942, but the fix for CVE-2013-1942 uses a blacklist for the jQuery parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-2022

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.23 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by using the alert function in the jQuery parameter. NOTE: these are the same parameters as CVE-2013-1942, but the fix for CVE-2013-1942 uses a blacklist for the jQuery parameter.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-2022

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jp ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-3jcq-cwr7-6332

больше 3 лет назад

jplayer Cross Site Scripting vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-2022

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.23 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by using the alert function in the jQuery parameter. NOTE: these are the same parameters as CVE-2013-1942, but the fix for CVE-2013-1942 uses a blacklist for the jQuery parameter.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2022

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.23 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by using the alert function in the jQuery parameter. NOTE: these are the same parameters as CVE-2013-1942, but the fix for CVE-2013-1942 uses a blacklist for the jQuery parameter.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-2022

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jp ...

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
github логотип
GHSA-3jcq-cwr7-6332

jplayer Cross Site Scripting vulnerability

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу