CVE-2011-3642
Summary
| CVE | CVE-2011-3642 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-08 16:15:00 UTC |
| Updated | 2020-02-12 16:54:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Flowplayer | Flowplayer Flash | All | All | All | All |
| Application | Flowplayer | Flowplayer Flash | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug #1103748 “included flowplayer 3.2.7 is vulnerable” : Bugs : Mahara | MISC | bugs.launchpad.net | Third Party Advisory |
| Flowplayer 'linkUrl' Parameter Cross Site Scripting Vulnerability | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Security Announcements - External vulnerability in Mahara flowplayer in <1.5.8 and <1.6.3 - Mahara ePortfolio System | MISC | mahara.org | Third Party Advisory |
| appsec.ws/Presentations/FlashFlooding.pdf | MISC | appsec.ws | Broken Link |
| Security Advisory SA52074 - Mahara Flowplayer Cross-Site Scripting Vulnerability - Secunia | MISC | secunia.com | Third Party Advisory |
| Issue 441 - flowplayer-core - Arbitrary plugins with remote code execution (XSS) - Flowplayer core - Google Project Hosting | MISC | code.google.com | Exploit, Third Party Advisory |
| Security Advisory SA58854 - TYPO3 News System Extension Flowplayer and Flashmedia Cross-Site Scripting Vulnerabilities - Secunia | MISC | secunia.com | Third Party Advisory |
| Flash Exploitation Database | MISC | web.appsec.ws | Broken Link |
| Security Advisory SA54206 - Flowplayer Flash "plugin" Domain Bypass Cross-Site Scripting Vulnerability - Secunia | MISC | secunia.com | Third Party Advisory |
| Cross-Site Scripting in news - - TYPO3 - The Enterprise Open Source CMS | MISC | typo3.org | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.