CVE-2011-3642

CRITICAL

Flowplayer Flash 3.2.7-3.2.16 - Cross-Site Scripting via Plugin Configuration Directive

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-3642. PoCs published by Szymon Gruszecki.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Flowplayer 3.2.7 by injecting malicious JavaScript code via the 'linkUrl' parameter in the SWF file's configuration. The payload executes arbitrary script code in the context of the affected site, allowing cookie theft or other client-side attacks.

Description

Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Szymon Gruszecki · textwebappsmultiple
https://www.exploit-db.com/exploits/35941

This exploit demonstrates a cross-site scripting (XSS) vulnerability in Flowplayer 3.2.7 by injecting malicious JavaScript code via the 'linkUrl' parameter in the SWF file's configuration. The payload executes arbitrary script code in the context of the affected site, allowing cookie theft or other client-side attacks.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Flowplayer 3.2.7
No auth needed
Prerequisites: Victim must visit a crafted URL with the malicious payload
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (10)

Core 10
Core References
Broken Link x_refsource_misc
http://web.appsec.ws/FlashExploitDatabase.php
Exploit, Third Party Advisory x_refsource_misc
https://code.google.com/p/flowplayer-core/issues/detail?id=441
Third Party Advisory x_refsource_misc
https://mahara.org/interaction/forum/topic.php?id=5237
Third Party Advisory x_refsource_misc
http://secunia.com/advisories/52074
Third Party Advisory x_refsource_misc
http://secunia.com/advisories/54206
Third Party Advisory x_refsource_misc
http://secunia.com/advisories/58854
Third Party Advisory, VDB Entry x_refsource_misc
https://www.securityfocus.com/bid/48651
Third Party Advisory x_refsource_misc
https://bugs.launchpad.net/mahara/+bug/1103748

Scores

CVSS v3 9.6
EPSS 0.0769
EPSS Percentile 92.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (1)
flowplayer/flowplayer_flash 3.2.7 - 3.2.16 (2 CPE variants)
Published Feb 08, 2020
Tracked Since Feb 18, 2026