Vulnerability Details CVE-2012-5882
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader.swf, a similar issue to CVE-2010-4208.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.7%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2012-5882
-
cpe:2.3:a:yahoo:yui:2.4.0
-
cpe:2.3:a:yahoo:yui:2.4.1
-
cpe:2.3:a:yahoo:yui:2.5.0
-
cpe:2.3:a:yahoo:yui:2.5.1
-
cpe:2.3:a:yahoo:yui:2.5.2
-
cpe:2.3:a:yahoo:yui:2.6.0
-
cpe:2.3:a:yahoo:yui:2.7.0
-
cpe:2.3:a:yahoo:yui:2.8.0
-
cpe:2.3:a:yahoo:yui:2.8.1
-
cpe:2.3:a:yahoo:yui:2.8.2
-
cpe:2.3:a:yahoo:yui:2.9.0