4.3
CVSSv2

CVE-2013-6780

Published: 13/11/2013 Updated: 28/07/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 up to and including 2.9.0 allows remote malicious users to inject arbitrary web script or HTML via the allowedDomain parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

yahoo yui 2.5.0

yahoo yui 2.5.1

yahoo yui 2.8.2

yahoo yui 2.9.0

yahoo yui 2.6.0

yahoo yui 2.8.0

yahoo yui 2.5.2

yahoo yui 2.7.0

yahoo yui 2.8.1

Vendor Advisories

Debian Bug report logs - #730104 yui: CVE-2013-6780 Package: yui; Maintainer for yui is (unknown); Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 21 Nov 2013 13:21:07 UTC Severity: grave Tags: security Fixed in version 290dfsg01-01+rm Done: Debian FTP Masters <ftpmaster@ftp-masterdebianorg> Bu ...

Exploits

Cisco Ironport AsyncOS suffers from a cross site scripting vulnerability ...