Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-2399
Description:Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.
Test IDs: 1.3.6.1.4.1.25623.1.0.71272  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-2399
BugTraq ID: 53192
http://www.securityfocus.com/bid/53192
Debian Security Information: DSA-2470 (Google Search)
http://www.debian.org/security/2012/dsa-2470
http://seclists.org/fulldisclosure/2013/Mar/110
http://jvn.jp/en/jp/JVN25280162/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2012-002110
http://packetstormsecurity.com/files/120746/SWFUpload-Content-Spoofing-Cross-Site-Scripting.html
http://packetstormsecurity.com/files/122399/tinymce11-xss.txt
http://www.openwall.com/lists/oss-security/2013/07/18/13
http://osvdb.org/81459
http://www.osvdb.org/91134
http://secunia.com/advisories/49138
XForce ISS Database: wordpress-swfupload-unspecified(75210)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75210




© 1998-2025 E-Soft Inc. All rights reserved.