CVE-2013-3565
Description
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua.
Risk Information
Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.396
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities affected in VLC Media Player (X64) 2.0.6 | Windows |
| Multiple vulnerabilities affected in VLC Media Player 2.0.6 | Windows |
| Multiple Vulnerabilities are affected in VLC Media Player (X64) 2.0.6 | Windows |
| Multiple Vulnerabilities are affected in VLC Media Player 2.0.6 | Windows |
| Multiple Vulnerabilities are affected in VLC Media Player (MSI) (x64) 2.0.6 | Windows |
| Multiple Vulnerabilities are affected in VLC media player (MSI) 2.0.6 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-339135 | VLC Media Player (X64) (3.0.21) |
| PATCH-339134 | VLC Media Player (3.0.21) |
| PATCH-327882 | VLC Media Player (X64) (3.0.18) |
| PATCH-327878 | VLC Media Player (3.0.18) |
| PATCH-334048 | VLC media player (MSI) (x64) (3.0.20.0) |
| PATCH-334050 | VLC media player (MSI) (3.0.20.0) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234