Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.71272
Category:FreeBSD Local Security Checks
Title:FreeBSD Ports: wordpress
Summary:The remote host is missing an update to the system; as announced in the referenced advisory.
Description:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: wordpress

CVE-2012-2399
Unspecified vulnerability in wp-includes/js/swfupload/swfupload.swf in
WordPress before 3.3.2 has unknown impact and attack vectors.
CVE-2012-2400
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress
before 3.3.2 has unknown impact and attack vectors.
CVE-2012-2401
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in
WordPress before 3.3.2 and other products, enables scripting
regardless of the domain from which the SWF content was loaded, which
allows remote attackers to bypass the Same Origin Policy via crafted
content.
CVE-2012-2402
wp-admin/plugins.php in WordPress before 3.3.2 allows remote
authenticated site administrators to bypass intended access
restrictions and deactivate network-wide plugins via unspecified
vectors.
CVE-2012-2403
wp-includes/formatting.php in WordPress before 3.3.2 attempts to
enable clickable links inside attributes, which makes it easier for
remote attackers to conduct cross-site scripting (XSS) attacks via
unspecified vectors.
CVE-2012-2404
wp-comments-post.php in WordPress before 3.3.2 supports offsite
redirects, which makes it easier for remote attackers to conduct
cross-site scripting (XSS) attacks via unspecified vectors.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-2399
BugTraq ID: 53192
http://www.securityfocus.com/bid/53192
Debian Security Information: DSA-2470 (Google Search)
http://www.debian.org/security/2012/dsa-2470
http://seclists.org/fulldisclosure/2013/Mar/110
http://jvn.jp/en/jp/JVN25280162/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2012-002110
http://packetstormsecurity.com/files/120746/SWFUpload-Content-Spoofing-Cross-Site-Scripting.html
http://packetstormsecurity.com/files/122399/tinymce11-xss.txt
http://www.openwall.com/lists/oss-security/2013/07/18/13
http://osvdb.org/81459
http://www.osvdb.org/91134
http://secunia.com/advisories/49138
XForce ISS Database: wordpress-swfupload-unspecified(75210)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75210
Common Vulnerability Exposure (CVE) ID: CVE-2012-2400
http://osvdb.org/81460
XForce ISS Database: wordpress-swfobject-unspecified(75209)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75209
Common Vulnerability Exposure (CVE) ID: CVE-2012-2401
https://nealpoole.com/blog/2012/05/xss-and-csrf-via-swf-applets-swfupload-plupload/
http://osvdb.org/81461
XForce ISS Database: wordpress-plupload-sec-bypass(75208)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75208
Common Vulnerability Exposure (CVE) ID: CVE-2012-2402
http://osvdb.org/81462
http://secunia.com/advisories/48957
XForce ISS Database: wordpress-plugins-sec-bypass(75207)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75207
XForce ISS Database: wordpress-plugins-security-bypass(75090)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75090
Common Vulnerability Exposure (CVE) ID: CVE-2012-2403
http://osvdb.org/81463
XForce ISS Database: wordpress-formatting-xss(75206)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75206
XForce ISS Database: wordpress-url-xss(75093)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75093
Common Vulnerability Exposure (CVE) ID: CVE-2012-2404
http://osvdb.org/81464
XForce ISS Database: wordpress-wpcommentspostphp-xss(75202)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75202
XForce ISS Database: wordpress-wpredirect-xss(75092)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75092
CopyrightCopyright (C) 2012 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.