CVE-2011-3642
CRITICALFlowplayer Flash 3.2.7-3.2.16 - Cross-Site Scripting via Plugin Configuration Directive
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-3642. PoCs published by Szymon Gruszecki.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Flowplayer 3.2.7 by injecting malicious JavaScript code via the 'linkUrl' parameter in the SWF file's configuration. The payload executes arbitrary script code in the context of the affected site, allowing cookie theft or other client-side attacks.
Description
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Flowplayer 3.2.7 by injecting malicious JavaScript code via the 'linkUrl' parameter in the SWF file's configuration. The payload executes arbitrary script code in the context of the affected site, allowing cookie theft or other client-side attacks.
References (10)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H