CVE-2012-5881

YUI 2.4.0-2.9.0 - Cross-Site Scripting via charts.swf

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56385
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/80118

Scores

EPSS 0.0245
EPSS Percentile 82.7%

Details

CWE
CWE-79
Status published
Products (12)
npm/yui2 2.4.0npm
yahoo/yui 2.4.0
yahoo/yui 2.4.1
yahoo/yui 2.5.0
yahoo/yui 2.5.1
yahoo/yui 2.5.2
yahoo/yui 2.6.0
yahoo/yui 2.7.0
yahoo/yui 2.8.0
yahoo/yui 2.8.1 (2 CPE variants)
... and 2 more
Published Nov 16, 2012
Tracked Since Feb 18, 2026