WordPress Multiple Remote Vulnerabilities
BID:53192
Info
WordPress Multiple Remote Vulnerabilities
| Bugtraq ID: | 53192 |
| Class: | Unknown |
| CVE: |
CVE-2012-2399 CVE-2012-2400 CVE-2012-2401 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 20 2012 12:00AM |
| Updated: | Apr 16 2015 05:43PM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
WordPress WordPress 3.1.4 WordPress WordPress 3.1.3 WordPress WordPress 3.1.2 WordPress WordPress 3.1.1 WordPress WordPress 3.0.5 WordPress WordPress 3.0.4 WordPress WordPress 3.0.3 WordPress WordPress 3.0.2 WordPress WordPress 2.9.2 WordPress WordPress 2.9.1 WordPress WordPress 2.8.6 WordPress WordPress 2.8.5 WordPress WordPress 2.8.4 WordPress WordPress 2.8.3 WordPress WordPress 2.8.2 WordPress WordPress 2.8.1 WordPress WordPress 2.6.5 WordPress WordPress 2.6.2 WordPress WordPress 2.6.1 WordPress WordPress 2.5.1 WordPress WordPress 2.3.3 WordPress WordPress 2.3.2 WordPress WordPress 2.3.1 WordPress WordPress 2.2.3 WordPress WordPress 2.2.2 WordPress WordPress 2.2.1 WordPress WordPress 2.1.3 WordPress WordPress 2.1.2 WordPress WordPress 2.1.1 WordPress WordPress 2.0.11 WordPress WordPress 2.0.10 WordPress WordPress 2.0.7 WordPress WordPress 2.0.6 WordPress WordPress 2.0.5 WordPress WordPress 2.0.4 WordPress WordPress 2.0.3 WordPress WordPress 2.0.2 WordPress WordPress 2.0.1 WordPress WordPress 2.0 WordPress WordPress 1.5.2 WordPress WordPress 1.5.1 .3 WordPress WordPress 1.5.1 .2 WordPress WordPress 1.5.1 WordPress WordPress 1.5 WordPress WordPress 1.3.1 WordPress WordPress 1.2.2 WordPress WordPress 1.2.2 WordPress WordPress 1.2.1 WordPress WordPress 1.2 WordPress WordPress 3.3.1 WordPress WordPress 3.3 WordPress WordPress 3.2-RC3 WordPress WordPress 3.2-RC1 WordPress WordPress 3.1.3 WordPress WordPress 3.1 WordPress WordPress 3.0.6 WordPress WordPress 3.0.4 WordPress WordPress 3.0.3 WordPress WordPress 3.0.2 WordPress WordPress 3.0.1 WordPress WordPress 3.0 WordPress WordPress 2.9.1.1 WordPress WordPress 2.9 WordPress WordPress 2.8.5.2 WordPress WordPress 2.8.5.1 WordPress WordPress 2.8.4 A WordPress WordPress 2.8 WordPress WordPress 2.7.1 WordPress WordPress 2.7 WordPress WordPress 2.6.3 WordPress WordPress 2.6 WordPress WordPress 2.5 WordPress WordPress 2.3 WordPress WordPress 2.2 Revision 5003 WordPress WordPress 2.2 Revision 5002 WordPress WordPress 2.2 WordPress WordPress 2.1.3-RC2 WordPress WordPress 2.1.3-RC1 WordPress WordPress 2.1 WordPress WordPress 2.0.9 WordPress WordPress 2.0.8 WordPress WordPress 2.0.10-RC2 WordPress WordPress 2.0.10-RC1 WordPress WordPress 2.0 WordPress WordPress 1.5.1.1 WordPress WordPress 1.5 WordPress WordPress 1.3.3 WordPress WordPress 1.3.2 WordPress WordPress 1.3 WordPress WordPress 1.2.5 A WordPress WordPress 1.2.5 WordPress WordPress 1.2.4 WordPress WordPress 1.2.3 WordPress WordPress 1.1.1 WordPress WordPress 1.0.2 WordPress WordPress 1.0.1 WordPress WordPress 1.0 WordPress Comment Extra Fields 1.7 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
WordPress WordPress 3.3.2 |
Discussion
WordPress Multiple Remote Vulnerabilities
WordPress is prone to prone to multiple remote vulnerabilities that includes multiple unspecified security vulnerabilities, multiple cross-site scripting vulnerabilities, and a security-bypass vulnerability.
Attackers can exploit the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials or launch other attacks.
Attackers can exploit the security-bypass issue to bypass security restrictions and perform unauthorized actions.
Versions prior to Wordpress 3.3.2 are vulnerable.
WordPress is prone to prone to multiple remote vulnerabilities that includes multiple unspecified security vulnerabilities, multiple cross-site scripting vulnerabilities, and a security-bypass vulnerability.
Attackers can exploit the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials or launch other attacks.
Attackers can exploit the security-bypass issue to bypass security restrictions and perform unauthorized actions.
Versions prior to Wordpress 3.3.2 are vulnerable.
Exploit / POC
WordPress Multiple Remote Vulnerabilities
Attackers can exploit these issues with a browser. To successfully exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues with a browser. To successfully exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
WordPress Multiple Remote Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
WordPress Multiple Remote Vulnerabilities
References:
References:
- Comment Extra Fields Product Page (WordPress)
- Version 3.3.2 (Wordpress)
- wordpress: Security fixes in version 3.3.2 (Debian)