Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-3439
Description:Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2015.236   1.3.6.1.4.1.25623.1.0.805986   1.3.6.1.4.1.25623.1.0.805985  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-3439
BugTraq ID: 74269
http://www.securityfocus.com/bid/74269
Debian Security Information: DSA-3250 (Google Search)
http://www.debian.org/security/2015/dsa-3250
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157391.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158278.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158271.html
http://zoczus.blogspot.com/2015/04/plupload-same-origin-method-execution.html
https://wpvulndb.com/vulnerabilities/7933
http://www.securitytracker.com/id/1032207




© 1998-2025 E-Soft Inc. All rights reserved.