← Back

CVE-2013-2022

nvd nist
Published: Aug 17, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.23 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by using the alert function in the jQuery parameter. NOTE: these are the same parameters as CVE-2013-1942, but the fix for CVE-2013-1942 uses a blacklist for the jQuery parameter.

Affected (69)

Products: Happyworm: Jplayer
1 product
Jplayer
Configuration A
69 vulnerable
Vulnerable SoftwareAffected Versions
Happyworm
Up to 2.2.22
Version 0.2.1 beta
Version 0.2.2 beta
Version 0.2.3 beta
Version 0.2.4 beta
Version 0.2.5 beta
Version 1.0.0
Version 1.1.0
Version 1.1.1
Version 1.2.0
Version 2.0.0
Version 2.0.10
Version 2.0.11
Version 2.0.12
Version 2.0.13
Version 2.0.14
Version 2.0.15
Version 2.0.16
Version 2.0.17
Version 2.0.18
Version 2.0.19
Version 2.0.1
Version 2.0.20
Version 2.0.21
Version 2.0.22
Version 2.0.23
Version 2.0.24
Version 2.0.25
Version 2.0.26
Version 2.0.27
Version 2.0.28
Version 2.0.29
Version 2.0.2
Version 2.0.30
Version 2.0.31
Version 2.0.32
Version 2.0.33
Version 2.0.34
Version 2.0.35
Version 2.0.36
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.0.9
Version 2.1.0
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1.6
Version 2.2.0
Version 2.2.10
Version 2.2.11
Version 2.2.12
Version 2.2.13
Version 2.2.14
Version 2.2.15
Version 2.2.16
Version 2.2.17
Version 2.2.18
Version 2.2.19
Version 2.2.1
Version 2.2.20
Version 2.2.21
Version 2.2.2

Timeline

No history available yet.