Vulnerability Description
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flowplayer | Flowplayer Flash | >= 3.2.7, <= 3.2.16 |
Related Weaknesses (CWE)
References
- http://appsec.ws/Presentations/FlashFlooding.pdfBroken Link
- http://secunia.com/advisories/52074Third Party Advisory
- http://secunia.com/advisories/54206Third Party Advisory
- http://secunia.com/advisories/58854Third Party Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-saBroken Link
- http://web.appsec.ws/FlashExploitDatabase.phpBroken Link
- https://bugs.launchpad.net/mahara/+bug/1103748Third Party Advisory
- https://code.google.com/p/flowplayer-core/issues/detail?id=441ExploitThird Party Advisory
- https://mahara.org/interaction/forum/topic.php?id=5237Third Party Advisory
- https://www.securityfocus.com/bid/48651Third Party AdvisoryVDB Entry
- http://appsec.ws/Presentations/FlashFlooding.pdfBroken Link
- http://secunia.com/advisories/52074Third Party Advisory
- http://secunia.com/advisories/54206Third Party Advisory
- http://secunia.com/advisories/58854Third Party Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-saBroken Link
FAQ
What is CVE-2011-3642?
CVE-2011-3642 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web scr...
How severe is CVE-2011-3642?
CVE-2011-3642 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2011-3642?
Check the references section above for vendor advisories and patch information. Affected products include: Flowplayer Flowplayer Flash.