CVE-2013-6853: XSS
Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is stored by the victim.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6853?
CVE-2013-6853 has a moderate severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-6853?
To fix CVE-2013-6853, users should update to the latest version of the Yahoo Toolbar.
What types of attacks can CVE-2013-6853 facilitate?
CVE-2013-6853 can facilitate cross-site scripting attacks that allow attackers to inject arbitrary web scripts or HTML.
Which versions of Yahoo Toolbar are affected by CVE-2013-6853?
CVE-2013-6853 affects Yahoo Toolbar versions 3.1.0.20130813024103 for Mac and 2.5.9.2013418100420 for Windows.
Who can exploit CVE-2013-6853?
Remote attackers can exploit CVE-2013-6853 by crafting specific URLs that are stored by unsuspecting victims.