4.3
CVSSv2

CVE-2013-1942

Published: 15/08/2013 Updated: 08/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer prior to 2.2.20, as used in ownCloud Server prior to 5.0.4 and other products, allow remote malicious users to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, as demonstrated using document.write in the jQuery parameter, a different vulnerability than CVE-2013-2022 and CVE-2013-2023.

Vulnerable Product Search on Vulmon Subscribe to Product

happyworm jplayer 2.1.6

happyworm jplayer 2.1.0

happyworm jplayer 2.0.7

happyworm jplayer 2.0.8

happyworm jplayer 2.0.16

happyworm jplayer 2.0.17

happyworm jplayer 2.0.24

happyworm jplayer 2.0.25

happyworm jplayer 2.0.32

happyworm jplayer 2.0.33

happyworm jplayer 2.1.4

happyworm jplayer 2.1.5

happyworm jplayer 2.0.5

happyworm jplayer 2.0.6

happyworm jplayer 2.0.13

happyworm jplayer 2.0.14

happyworm jplayer 2.0.15

happyworm jplayer 2.0.22

happyworm jplayer 2.0.23

happyworm jplayer 2.0.30

happyworm jplayer 2.0.31

happyworm jplayer 1.1.1

happyworm jplayer 1.1.0

happyworm jplayer 2.2.1

happyworm jplayer 2.2.2

happyworm jplayer 2.2.9

happyworm jplayer 2.2.10

happyworm jplayer 2.2.18

happyworm jplayer

happyworm jplayer 2.2.0

happyworm jplayer 2.1.1

happyworm jplayer 2.0.1

happyworm jplayer 2.0.2

happyworm jplayer 2.0.9

happyworm jplayer 2.0.10

happyworm jplayer 2.0.18

happyworm jplayer 2.0.19

happyworm jplayer 2.0.26

happyworm jplayer 2.0.27

happyworm jplayer 2.0.34

happyworm jplayer 2.0.35

happyworm jplayer 0.2.4

happyworm jplayer 0.2.3

happyworm jplayer 2.2.5

happyworm jplayer 2.2.6

happyworm jplayer 2.2.13

happyworm jplayer 2.2.14

happyworm jplayer 2.2.15

happyworm jplayer 1.0.0

happyworm jplayer 0.2.5

happyworm jplayer 2.2.3

happyworm jplayer 2.2.4

happyworm jplayer 2.2.11

happyworm jplayer 2.2.12

happyworm jplayer 2.1.2

happyworm jplayer 2.1.3

happyworm jplayer 2.0.3

happyworm jplayer 2.0.4

happyworm jplayer 2.0.11

happyworm jplayer 2.0.12

happyworm jplayer 2.0.20

happyworm jplayer 2.0.21

happyworm jplayer 2.0.28

happyworm jplayer 2.0.29

happyworm jplayer 2.0.36

happyworm jplayer 2.0.0

happyworm jplayer 1.2.0

happyworm jplayer 0.2.2

happyworm jplayer 0.2.1

happyworm jplayer 2.2.7

happyworm jplayer 2.2.8

happyworm jplayer 2.2.16

happyworm jplayer 2.2.17

owncloud owncloud 4.5.6

owncloud owncloud 4.5.5

owncloud owncloud 4.5.10

owncloud owncloud 4.5.1

owncloud owncloud 4.0.3

owncloud owncloud 4.0.2

owncloud owncloud 4.0.10

owncloud owncloud 4.0.1

owncloud owncloud 5.0.2

owncloud owncloud 5.0.0

owncloud owncloud 4.5.9

owncloud owncloud 4.5.2

owncloud owncloud 4.5.13

owncloud owncloud 4.0.7

owncloud owncloud 4.0.6

owncloud owncloud 4.0.14

owncloud owncloud 4.0.13

owncloud owncloud 3.0.2

owncloud owncloud 3.0.1

owncloud owncloud 5.0.1

owncloud owncloud 4.5.4

owncloud owncloud 4.5.3

owncloud owncloud 4.5.0

owncloud owncloud 4.0.9

owncloud owncloud 4.0.8

owncloud owncloud 4.0.16

owncloud owncloud 4.0.15

owncloud owncloud 4.0.0

owncloud owncloud 3.0.3

owncloud owncloud 4.5.8

owncloud owncloud 4.5.7

owncloud owncloud 4.5.12

owncloud owncloud 4.5.11

owncloud owncloud 4.0.5

owncloud owncloud 4.0.4

owncloud owncloud 4.0.12

owncloud owncloud 4.0.11

owncloud owncloud 3.0.0

owncloud owncloud

Exploits

source: wwwsecurityfocuscom/bid/59030/info jPlayer is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may allow the attacker to s ...
jPlayer versions prior to 2223 suffers from cross site scripting and content spoofing vulnerabilities ...