CVE-2012-2399
Summary
| CVE | CVE-2012-2399 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-04-21 23:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wordpress | Wordpress | 0.71 | All | All | All |
| Application | Wordpress | Wordpress | 1.0 | All | All | All |
| Application | Wordpress | Wordpress | 1.0.1 | All | All | All |
| Application | Wordpress | Wordpress | 1.0.2 | All | All | All |
| Application | Wordpress | Wordpress | 1.1.1 | All | All | All |
| Application | Wordpress | Wordpress | 1.2 | All | All | All |
| Application | Wordpress | Wordpress | 1.2.1 | All | All | All |
| Application | Wordpress | Wordpress | 1.2.2 | All | All | All |
| Application | Wordpress | Wordpress | 1.2.3 | All | All | All |
| Application | Wordpress | Wordpress | 1.2.4 | All | All | All |
| Application | Wordpress | Wordpress | 1.2.5 | All | All | All |
| Application | Wordpress | Wordpress | 1.2.5 | a | All | All |
| Application | Wordpress | Wordpress | 1.3 | All | All | All |
| Application | Wordpress | Wordpress | 1.3.2 | All | All | All |
| Application | Wordpress | Wordpress | 1.3.3 | All | All | All |
| Application | Wordpress | Wordpress | 1.5 | All | All | All |
| Application | Wordpress | Wordpress | 1.5.1 | All | All | All |
| Application | Wordpress | Wordpress | 1.5.1.1 | All | All | All |
| Application | Wordpress | Wordpress | 1.5.1.2 | All | All | All |
| Application | Wordpress | Wordpress | 1.5.1.3 | All | All | All |
| Application | Wordpress | Wordpress | 1.5.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.0 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.10 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.11 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.4 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.5 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.6 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.7 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.8 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.9 | All | All | All |
| Application | Wordpress | Wordpress | 2.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.1.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.1.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.1.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.2.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.2.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.2.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.3.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.3.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.3.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.5 | All | All | All |
| Application | Wordpress | Wordpress | 2.5.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.6 | All | All | All |
| Application | Wordpress | Wordpress | 2.6.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.6.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.6.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.6.5 | All | All | All |
| Application | Wordpress | Wordpress | 2.7 | All | All | All |
| Application | Wordpress | Wordpress | 2.7.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.8 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.4 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.4 | a | All | All |
| Application | Wordpress | Wordpress | 2.8.5 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.5.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.5.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.6 | All | All | All |
| Application | Wordpress | Wordpress | 2.9 | All | All | All |
| Application | Wordpress | Wordpress | 2.9.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.9.1.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.9.2 | All | All | All |
| Application | Wordpress | Wordpress | 3.0 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.1 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.2 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.3 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.4 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.5 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.6 | All | All | All |
| Application | Wordpress | Wordpress | 3.1 | All | All | All |
| Application | Wordpress | Wordpress | 3.1.1 | All | All | All |
| Application | Wordpress | Wordpress | 3.1.2 | All | All | All |
| Application | Wordpress | Wordpress | 3.1.3 | All | All | All |
| Application | Wordpress | Wordpress | 3.3 | All | All | All |
| Application | Wordpress | Wordpress | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/81459 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| oss-security - Re: Re: SWFUpload <= (Object Injection/CSRF) Vulnerabilities Multiple flaws | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Debian -- Security Information -- DSA-2470-1 wordpress | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| jvndb.jvn.jp/jvndb/JVNDB-2012-002110 | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| Full Disclosure: CS and XSS vulnerabilities in SWFUpload | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| swfupload.swf in branches/3.3/wp-includes/js/swfupload – WordPress Trac | af854a3a-2127-422b-91ae-364da2661108 | core.trac.wordpress.org | |
| WordPress Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| WordPress › WordPress 3.3.2 (and WordPress 3.4 Beta 3) | af854a3a-2127-422b-91ae-364da2661108 | wordpress.org | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| TinyMCE Image Manager 1.1 Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| WordPress › Announcing a secure SWFUpload fork « Make WordPress Core | af854a3a-2127-422b-91ae-364da2661108 | make.wordpress.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| JVN#25280162: WordPress vulnerable to cross-site scripting | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| SWFUpload Content Spoofing / Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| www.osvdb.org/91134 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.