CVE-2011-4568 Information

Share on:

Description

Cross-site scripting (XSS) vulnerability in view/frontend-head.php in the Flowplayer plugin before 1.2.12 for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI.

Reference

http://plugins.trac.wordpress.org/changeset?reponame=&new=41360740fv-wordpress-flowplayer&old=40959440fv-wordpress-flowplayer http://secunia.com/advisories/46346 http://wordpress.org/extend/plugins/fv-wordpress-flowplayer/changelog/ http://www.securityfocus.com/bid/50008