CVE-2013-1636 | CiviCRM up to 4.3.3 open-flash-chart.swf get-data cross site scripting (Advisory 120433 / EDB-38324)
A vulnerability was found in CiviCRM. It has been classified as problematic. Affected is an unknown function of the file open-flash-chart.swf. The manipulation of the argument get-data leads to cross site scripting.
This vulnerability is traded as CVE-2013-1636. It is possible to launch the attack remotely. Furthermore, there is an exploit available.