CVE-2012-2399

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.
References
Link Resource
http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/swfupload/swfupload.swf?rev=20503
http://jvn.jp/en/jp/JVN25280162/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2012-002110
http://make.wordpress.org/core/2013/06/21/secure-swfupload/
http://osvdb.org/81459
http://packetstormsecurity.com/files/120746/SWFUpload-Content-Spoofing-Cross-Site-Scripting.html
http://packetstormsecurity.com/files/122399/tinymce11-xss.txt
http://seclists.org/fulldisclosure/2013/Mar/110
http://secunia.com/advisories/49138
http://wordpress.org/news/2012/04/wordpress-3-3-2/ Patch Vendor Advisory
http://www.debian.org/security/2012/dsa-2470
http://www.openwall.com/lists/oss-security/2013/07/18/13
http://www.osvdb.org/91134
http://www.securityfocus.com/bid/53192
https://exchange.xforce.ibmcloud.com/vulnerabilities/75210
http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/swfupload/swfupload.swf?rev=20503
http://jvn.jp/en/jp/JVN25280162/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2012-002110
http://make.wordpress.org/core/2013/06/21/secure-swfupload/
http://osvdb.org/81459
http://packetstormsecurity.com/files/120746/SWFUpload-Content-Spoofing-Cross-Site-Scripting.html
http://packetstormsecurity.com/files/122399/tinymce11-xss.txt
http://seclists.org/fulldisclosure/2013/Mar/110
http://secunia.com/advisories/49138
http://wordpress.org/news/2012/04/wordpress-3-3-2/ Patch Vendor Advisory
http://www.debian.org/security/2012/dsa-2470
http://www.openwall.com/lists/oss-security/2013/07/18/13
http://www.osvdb.org/91134
http://www.securityfocus.com/bid/53192
https://exchange.xforce.ibmcloud.com/vulnerabilities/75210
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.5:a:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.5:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.6:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.6.5:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.7:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.8:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.8.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.8.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.8.4:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.8.4:a:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.8.5:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.8.5.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.8.5.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.8.6:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.9:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.9.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.9.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.9.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.0:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:3.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:39

Type Values Removed Values Added
References () http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/swfupload/swfupload.swf?rev=20503 - () http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/swfupload/swfupload.swf?rev=20503 -
References () http://jvn.jp/en/jp/JVN25280162/index.html - () http://jvn.jp/en/jp/JVN25280162/index.html -
References () http://jvndb.jvn.jp/jvndb/JVNDB-2012-002110 - () http://jvndb.jvn.jp/jvndb/JVNDB-2012-002110 -
References () http://make.wordpress.org/core/2013/06/21/secure-swfupload/ - () http://make.wordpress.org/core/2013/06/21/secure-swfupload/ -
References () http://osvdb.org/81459 - () http://osvdb.org/81459 -
References () http://packetstormsecurity.com/files/120746/SWFUpload-Content-Spoofing-Cross-Site-Scripting.html - () http://packetstormsecurity.com/files/120746/SWFUpload-Content-Spoofing-Cross-Site-Scripting.html -
References () http://packetstormsecurity.com/files/122399/tinymce11-xss.txt - () http://packetstormsecurity.com/files/122399/tinymce11-xss.txt -
References () http://seclists.org/fulldisclosure/2013/Mar/110 - () http://seclists.org/fulldisclosure/2013/Mar/110 -
References () http://secunia.com/advisories/49138 - () http://secunia.com/advisories/49138 -
References () http://wordpress.org/news/2012/04/wordpress-3-3-2/ - Patch, Vendor Advisory () http://wordpress.org/news/2012/04/wordpress-3-3-2/ - Patch, Vendor Advisory
References () http://www.debian.org/security/2012/dsa-2470 - () http://www.debian.org/security/2012/dsa-2470 -
References () http://www.openwall.com/lists/oss-security/2013/07/18/13 - () http://www.openwall.com/lists/oss-security/2013/07/18/13 -
References () http://www.osvdb.org/91134 - () http://www.osvdb.org/91134 -
References () http://www.securityfocus.com/bid/53192 - () http://www.securityfocus.com/bid/53192 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/75210 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/75210 -

Information

Published : 2012-04-21 23:55

Updated : 2024-11-21 01:39


NVD link : CVE-2012-2399

Mitre link : CVE-2012-2399

CVE.ORG link : CVE-2012-2399


JSON object : View

Products Affected

wordpress

  • wordpress