Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-2401
Description:Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.
Test IDs: 1.3.6.1.4.1.25623.1.0.71272  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-2401
BugTraq ID: 53192
http://www.securityfocus.com/bid/53192
Debian Security Information: DSA-2470 (Google Search)
http://www.debian.org/security/2012/dsa-2470
https://nealpoole.com/blog/2012/05/xss-and-csrf-via-swf-applets-swfupload-plupload/
http://osvdb.org/81461
http://secunia.com/advisories/49138
XForce ISS Database: wordpress-plupload-sec-bypass(75208)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75208




© 1998-2025 E-Soft Inc. All rights reserved.