CVE-2013-6780
13.11.2013, 15:55
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.
| Vendor | Product | Version |
|---|---|---|
| yahoo | yui | 2.5.0 |
| yahoo | yui | 2.5.1 |
| yahoo | yui | 2.5.2 |
| yahoo | yui | 2.6.0 |
| yahoo | yui | 2.7.0 |
| yahoo | yui | 2.8.0 |
| yahoo | yui | 2.8.1 |
| yahoo | yui | 2.8.2 |
| yahoo | yui | 2.9.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| maas |
| ||||||||||||||||||||||||
| yui |
| ||||||||||||||||||||||||
| yui3 |
|
References