CVE-2012-3351
MEDIUMJW Player < 5.10.2295 - Cross-Site Scripting via Link or Logo Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2012-3351. PoCs published by MustLive.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in JW Player by injecting a base64-encoded HTML payload via the 'abouttext' and 'aboutlink' parameters. The payload executes arbitrary JavaScript in the context of the affected site.
Description
Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) logo.link, or (3) aboutlink parameter, or a nested URI scheme name for (4) javascript, (5) asfunction, or (6) vbscript.
Exploits (2)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in JW Player by injecting a base64-encoded HTML payload via the 'abouttext' and 'aboutlink' parameters. The payload executes arbitrary JavaScript in the context of the affected site.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in JW Player by injecting arbitrary JavaScript code via the 'playerready' parameter in the SWF file URL. The PoC uses an alert to display the document cookie, proving the execution of arbitrary script code.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N