CVE-2012-6550
ZeroClipboard < 1.1.4 - Cross-Site Scripting via Flash Object clipText
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-6550. PoCs published by MustLive.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in ZeroClipboard SWF files prior to version 1.1.7. The crafted URL injects malicious ActionScript code via the 'id' parameter, leading to arbitrary JavaScript execution in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipText returned from the flash object," a different vulnerability than CVE-2013-1808.
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in ZeroClipboard SWF files prior to version 1.1.7. The crafted URL injects malicious ActionScript code via the 'id' parameter, leading to arbitrary JavaScript execution in the context of the affected site.