CVE-2012-0287
published 2012-01-06CVE-2012-0287: Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to…
PriorityP412low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
2.63%
83.8th percentile
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.3.1+dfsg-1 (bookworm) | wordpress 3.3.1+dfsg-1 (bookworm) |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 3.3.1+dfsg-1 | 3.3.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.3.1+dfsg-1 | 3.3.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.3.1+dfsg-1 | 3.3.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.3.1+dfsg-1 | 3.3.1+dfsg-1 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv2.6LOW
vendor_debian2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v76g-ww63-2j46: Cross-site scripting (XSS) vulnerability in wp-comments-post
ghsa_unreviewed·2022-05-04
CVE-2012-0287 [LOW] CWE-79 GHSA-v76g-ww63-2j46: Cross-site scripting (XSS) vulnerability in wp-comments-post
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.
OSV
CVE-2012-0287: Cross-site scripting (XSS) vulnerability in wp-comments-post
osv·2012-01-06·CVSS 2.6
CVE-2012-0287 [LOW] CVE-2012-0287: Cross-site scripting (XSS) vulnerability in wp-comments-post
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.
Debian
CVE-2012-0287: wordpress - Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3....
vendor_debian·2012·CVSS 2.6
CVE-2012-0287 [LOW] CVE-2012-0287: wordpress - Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3....
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.
Scope: local
bookworm: resolved (fixed in 3.3.1+dfsg-1)
bullseye: resolved (fixed in 3.3.1+dfsg-1)
forky: resolved (fixed in 3.3.1+dfsg-1)
sid: resolved (fixed in 3.3.1+dfsg-1)
trixie: resolved (fixed in 3.3.1+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1 [fedora-all]
bugzilla·2012-01-04·CVSS 2.6
CVE-2012-0287 [LOW] CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1 [fedora-all]
CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=771729
Bugzilla
CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1 [epel-6]
bugzilla·2012-01-04·CVSS 2.6
CVE-2012-0287 [LOW] CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1 [epel-6]
CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=771729
epel
Bugzilla
CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1
bugzilla·2012-01-04·CVSS 2.6
CVE-2012-0287 [LOW] CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1
CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1
An XSS flaw was reported [1] against Wordpress 3.3. Upstream has released 3.3.1 [2] to correct this flaw.
[1] http://oldmanlab.blogspot.com/2012/01/wordpress-33-xss-vulnerability.html
[2] https://wordpress.org/news/2012/01/wordpress-3-3-1/
Discussion:
Created wordpress tracking bugs for this issue
Affects: fedora-all [bug 771730]
Affects: epel-6 [bug 771731]
arXiv
Detection of Configuration Vulnerabilities in Distributed (Web) Environments
arxiv_fulltext·2012-07-12
Detection of Configuration Vulnerabilities in Distributed (Web) Environments
Detection of Configuration Vulnerabilities in Distributed (Web) Environments This work was partially
supported by the FP7-ICT-2009.1.4 Project PoSecCo (no. 257129,
.posecco.eu)
Detection of configuration vulnerabilities
Matteo Maria Casalino Michele Mangili Henrik Plate Serena
Elisa Ponta
SAP Research Sophia-Antipolis, 805 Avenue Dr M. Donat,
06250 Mougins, France matteo.maria.casalino,
henrik.plate, [email protected]
M. M. Casalino M. Mangili H. Plate S. E. Ponta
## Abstract
Many tools and libraries are readily available to build and operate
distributed Web applications. While the setup of operational
environments is comparatively easy, practice shows that their
continuous secure operation is more difficult to achieve, many times
resulting in vulnerable systems exposed to the Int
http://oldmanlab.blogspot.com/2012/01/wordpress-33-xss-vulnerability.htmlhttp://www.securityfocus.com/bid/51237http://www.securitytracker.com/id?1026542https://wordpress.org/news/2012/01/wordpress-3-3-1/http://oldmanlab.blogspot.com/2012/01/wordpress-33-xss-vulnerability.htmlhttp://www.securityfocus.com/bid/51237http://www.securitytracker.com/id?1026542https://wordpress.org/news/2012/01/wordpress-3-3-1/
2012-01-06
Published