Flowplayer Flowplayer Flash 3.2.16 for Typo3

CPE Details

Flowplayer Flowplayer Flash 3.2.16 for Typo3
3.2.16
2020-02-24
14h25 +00:00
2020-02-24
14h25 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:flowplayer:flowplayer_flash:3.2.16:*:*:*:*:typo3:*:*

Informations

Vendor

flowplayer

Product

flowplayer_flash

Version

3.2.16

Target Software

typo3

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2011-3642 2020-02-08 14h46 +00:00 Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.
9.6
Critique
CVE-2013-7341 2014-03-22 00h00 +00:00 Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.
4.3