10
CVSSv2

CVE-2012-2399

Published: 21/04/2012 Updated: 19/12/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 891
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and previous versions, as used in WordPress prior to 3.5.2, TinyMCE Image Manager 1.1 and previous versions, and other products allows remote malicious users to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress 2.8

wordpress wordpress 2.0.9

wordpress wordpress 2.0

wordpress wordpress 2.3.2

wordpress wordpress 2.0.6

wordpress wordpress 2.0.7

wordpress wordpress 2.8.5

wordpress wordpress 2.8.1

wordpress wordpress 3.1

wordpress wordpress 2.8.4

wordpress wordpress 3.0

wordpress wordpress 1.5

wordpress wordpress 1.2

wordpress wordpress 2.9.1

wordpress wordpress 1.0

wordpress wordpress 1.2.3

wordpress wordpress 1.2.4

wordpress wordpress 3.0.4

wordpress wordpress 2.8.5.1

wordpress wordpress 2.6.2

wordpress wordpress 2.0.8

wordpress wordpress 1.5.1.3

wordpress wordpress 1.5.2

wordpress wordpress 2.0.4

wordpress wordpress 2.0.5

wordpress wordpress 3.0.3

wordpress wordpress 2.8.3

wordpress wordpress 2.8.6

wordpress wordpress 2.6.3

wordpress wordpress 3.0.1

wordpress wordpress 3.0.2

wordpress wordpress 1.0.2

wordpress wordpress 2.9

wordpress wordpress 2.5

wordpress wordpress 1.2.5

wordpress wordpress 3.1.2

wordpress wordpress

wordpress wordpress 2.0.11

wordpress wordpress 2.2

wordpress wordpress 2.2.1

wordpress wordpress 2.0.1

wordpress wordpress 3.3

wordpress wordpress 2.1

wordpress wordpress 2.1.1

wordpress wordpress 2.8.2

wordpress wordpress 2.5.1

wordpress wordpress 2.3

wordpress wordpress 3.0.6

wordpress wordpress 2.6.1

wordpress wordpress 2.9.2

wordpress wordpress 1.5.1

wordpress wordpress 1.0.1

wordpress wordpress 2.6.5

wordpress wordpress 3.1.3

wordpress wordpress 1.1.1

wordpress wordpress 2.8.5.2

wordpress wordpress 1.3.3

wordpress wordpress 2.9.1.1

wordpress wordpress 1.3.2

wordpress wordpress 2.1.3

wordpress wordpress 2.2.3

wordpress wordpress 1.5.1.1

wordpress wordpress 2.3.1

wordpress wordpress 1.5.1.2

wordpress wordpress 2.0.10

wordpress wordpress 2.0.2

wordpress wordpress 2.1.2

wordpress wordpress 2.7

wordpress wordpress 2.3.3

wordpress wordpress 3.0.5

wordpress wordpress 2.6

wordpress wordpress 2.2.2

wordpress wordpress 1.2.1

wordpress wordpress 1.2.2

wordpress wordpress 0.71

wordpress wordpress 3.1.1

wordpress wordpress 2.7.1

wordpress wordpress 1.3

Vendor Advisories

Debian Bug report logs - #713947 wordpress: Multiple security issues Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 24 Jun 2013 06:39:02 UTC Severity: grave Tags: ...
Several vulnerabilities were identified in WordPress, a web blogging tool As the CVEs were allocated from releases announcements and specific fixes are usually not identified, it has been decided to upgrade the wordpress package to the latest upstream version instead of backporting the patches This means extra care should be taken when upgrading, ...

Exploits

WordPress WP-E-Commerce plugin version 3895 suffers from local file inclusion, cross site scripting, cross site request forgery, file upload, and code execution vulnerabilities ...

Github Repositories

SWFUpload - Fork from SWFUpload Build 2.2.1

SWFUpload SWFUpload - Fork from SWFUpload Build 221 Original Project at: codegooglecom/p/swfupload/ LICENCE Copyright (C) 2006-2007 Lars Huring, Olov Nilzén and Mammon Media Copyright (C) 2007-2008 Jake Roberts Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software&qu

A fork of the long-abandoned SWFUpload project, maintained by WordPress and others to ensure that a secure version of SWFUpload exists. Report security vulnerabilities to swfupload-security@wordpress.org.

SWFUpload (Maintained for Security Fixes) This is a fork of the long-abandoned SWFUpload project, maintained by WordPress and others to ensure that a secure version of SWFUpload exists We strongly suggest you do not use SWFUpload But if you must, use this fork WordPress is maintaining a secure version of SWFUpload for use by WordPress plugins that have yet to be updated to u