Vulnerability Name: | CVE-2013-3565 (CCN-175729) | ||||||||||||||||
Assigned: | 2013-04-08 | ||||||||||||||||
Published: | 2013-04-08 | ||||||||||||||||
Updated: | 2020-02-03 | ||||||||||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua. | ||||||||||||||||
CVSS v3 Severity: | 6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L/E:H/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-3565 Source: CCN Type: VLC GIT Repository lua http: fix two xss vulnerabilities Source: MISC Type: Patch, Third Party Advisory http://git.videolan.org/gitweb.cgi/vlc.git/?p=vlc.git;a=commitdiff;h=bf02b8dd211d5a52aa301a9a2ff4e73ed8195881 Source: MISC Type: Third Party Advisory http://lists.opensuse.org/opensuse-updates/2014-03/msg00001.html Source: MISC Type: Release Notes http://www.videolan.org/developers/vlc-branch/NEWS Source: XF Type: UNKNOWN videolan-cve20133565-xss(175729) Source: CCN Type: VideoLAN Web site VLC media player Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-3565 Source: MISC Type: Exploit, Third Party Advisory https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-007.txt | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |