This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Happyworm First view 2013-08-15
Product Jplayer Last view 2013-08-17
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:happyworm:jplayer:2.0.34:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.10:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.18:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.0:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.1.1:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.1:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.2:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.9:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.10:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.18:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.19:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.26:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.27:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.1.0:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.35:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:0.2.4:beta:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:0.2.3:beta:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.5:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.6:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.13:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.14:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.15:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:1.0.0:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:0.2.5:beta:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.3:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.2:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.1.6:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.7:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.8:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.16:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.17:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.24:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.25:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.32:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.33:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.1.4:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.1.5:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.5:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.6:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.13:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.14:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.15:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.22:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.23:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.30:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.0.31:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:1.1.1:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:1.1.0:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.1:*:*:*:*:*:*:* 3
cpe:2.3:a:happyworm:jplayer:2.2.9:*:*:*:*:*:*:* 3

Related : CVE

  Date Alert Description
4.3 2013-08-17 CVE-2013-2022

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.23 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by using the alert function in the jQuery parameter. NOTE: these are the same parameters as CVE-2013-1942, but the fix for CVE-2013-1942 uses a blacklist for the jQuery parameter.

4.3 2013-08-15 CVE-2013-2023

Cross-site scripting (XSS) vulnerability in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to incomplete blacklists, a different vulnerability than CVE-2013-1942 and CVE-2013-2022.

4.3 2013-08-15 CVE-2013-1942

Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as used in ownCloud Server before 5.0.4 and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, as demonstrated using document.write in the jQuery parameter, a different vulnerability than CVE-2013-2022 and CVE-2013-2023.

CWE : Common Weakness Enumeration

%idName
100% (3) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')