Beveiligingsadvies

CVE-2010-4396

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2010-12-14 15:00:00
Laatst bijgewerkt 2024-08-07 03:43:14
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Cross-zone scripting vulnerability in the HandleAction method in a certain ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 allows remote attackers to inject arbitrary web script or HTML in the Local Zone by specifying a local file in a NavigateToURL action, as demonstrated by a local skin file.