CVE-2013-6780
published 2013-11-13CVE-2013-6780: Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.42%
82.4th percentile
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
| yahoo | yui | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
XSS vulnerability in YUI 2.5.0 through 2.9.0
vendor_redhat·2013-11-11·CVSS 4.3
CVE-2013-6780 [MEDIUM] CWE-79 XSS vulnerability in YUI 2.5.0 through 2.9.0
XSS vulnerability in YUI 2.5.0 through 2.9.0
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.
Package: dojo (Red Hat Satellite 5.6) - Will not fix
GHSA
GHSA-8795-rjrm-xjf7: Cross-site scripting (XSS) vulnerability in uploader
ghsa_unreviewed·2022-05-17
CVE-2013-6780 [MEDIUM] CWE-79 GHSA-8795-rjrm-xjf7: Cross-site scripting (XSS) vulnerability in uploader
Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6780 moodle: XSS vulnerability in YUI 2.5.0 through 2.9.0 [epel-5]
bugzilla·2013-11-13·CVSS 4.3
CVE-2013-6780 [MEDIUM] CVE-2013-6780 moodle: XSS vulnerability in YUI 2.5.0 through 2.9.0 [epel-5]
CVE-2013-6780 moodle: XSS vulnerability in YUI 2.5.0 through 2.9.0 [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for
Bugzilla
CVE-2013-6780 dojo: XSS vulnerability in YUI 2.5.0 through 2.9.0 [epel-all]
bugzilla·2013-11-13·CVSS 4.3
CVE-2013-6780 [MEDIUM] CVE-2013-6780 dojo: XSS vulnerability in YUI 2.5.0 through 2.9.0 [epel-all]
CVE-2013-6780 dojo: XSS vulnerability in YUI 2.5.0 through 2.9.0 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
Bugzilla
CVE-2013-6780 dojo: XSS vulnerability in YUI 2.5.0 through 2.9.0 [fedora-all]
bugzilla·2013-11-13·CVSS 4.3
CVE-2013-6780 [MEDIUM] CVE-2013-6780 dojo: XSS vulnerability in YUI 2.5.0 through 2.9.0 [fedora-all]
CVE-2013-6780 dojo: XSS vulnerability in YUI 2.5.0 through 2.9.0 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2013-6780 moodle: XSS vulnerability in YUI 2.5.0 through 2.9.0 [fedora-18]
bugzilla·2013-11-13·CVSS 4.3
CVE-2013-6780 [MEDIUM] CVE-2013-6780 moodle: XSS vulnerability in YUI 2.5.0 through 2.9.0 [fedora-18]
CVE-2013-6780 moodle: XSS vulnerability in YUI 2.5.0 through 2.9.0 [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-18 tracking bug for
Bugzilla
CVE-2013-6780 XSS vulnerability in YUI 2.5.0 through 2.9.0
bugzilla·2013-11-13·CVSS 4.3
CVE-2013-6780 [MEDIUM] CVE-2013-6780 XSS vulnerability in YUI 2.5.0 through 2.9.0
CVE-2013-6780 XSS vulnerability in YUI 2.5.0 through 2.9.0
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-6780 to
the following vulnerability:
Name: CVE-2013-6780
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6780
Assigned: 20131112
Reference: https://yuilibrary.com/support/20131111-vulnerability/
Cross-site scripting (XSS) vulnerability in uploader.swf in the
Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote
attackers to inject arbitrary web script or HTML via the allowedDomain
parameter.
Upstream indicates that all YUI2 files should be removed and that YUI3, which is not vulnerable to this issue, should be used instead.
The dojo package contains an uploader.swf, and grepping in the source there is a reference to YUI in the LICENS
http://openwall.com/lists/oss-security/2013/11/25/1http://packetstormsecurity.com/files/130527/Cisco-Ironport-AsyncOS-Cross-Site-Scripting.htmlhttp://www.securitytracker.com/id/1029528https://yuilibrary.com/support/20131111-vulnerability/http://openwall.com/lists/oss-security/2013/11/25/1http://packetstormsecurity.com/files/130527/Cisco-Ironport-AsyncOS-Cross-Site-Scripting.htmlhttp://www.securitytracker.com/id/1029528https://yuilibrary.com/support/20131111-vulnerability/
2013-11-13
Published