CVE-2012-3351
Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) logo.link, or (3) aboutlink parameter, or a nested URI scheme name for…
Does this matter?
Lower severity and a low EPSS score (2.58%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) logo.link, or (3) aboutlink parameter, or a nested URI scheme name for (4) javascript, (5) asfunction, or (6) vbscript.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.58% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- longtailvideo/jw player
- Source
- cve@mitre.org
References
- http://developer.longtailvideo.com/trac/ticket/1585Vendor Advisory
- http://technet.microsoft.com/security/msvr/msvr12-009Third Party Advisory
- https://www.exploit-db.com/exploits/37552Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/37672Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/54101/discussThird Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/55199/exploitThird Party Advisory, VDB Entry
- http://developer.longtailvideo.com/trac/ticket/1585Vendor Advisory
- http://technet.microsoft.com/security/msvr/msvr12-009Third Party Advisory
- https://www.exploit-db.com/exploits/37552Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/37672Third Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/54101/discussThird Party Advisory, VDB Entry
- https://www.securityfocus.com/bid/55199/exploitThird Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.