CVE-2012-0287Cross-site Scripting in Wordpress

Severity
2.6LOWNVD
EPSS
0.6%
top 30.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 6
Latest updateMay 4

Description

Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages3 packages

debiandebian/wordpress< wordpress 3.3.1+dfsg-1 (bookworm)
Debianwordpress/wordpress< 3.3.1+dfsg-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v76g-ww63-2j46: Cross-site scripting (XSS) vulnerability in wp-comments-post2022-05-04
OSV
CVE-2012-0287: Cross-site scripting (XSS) vulnerability in wp-comments-post2012-01-06

📋Vendor Advisories

1
Debian
CVE-2012-0287: wordpress - Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3....2012

📄Research Papers

1
arXiv
Detection of Configuration Vulnerabilities in Distributed (Web) Environments2012-07-12

💬Community

3
Bugzilla
CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1 [fedora-all]2012-01-04
Bugzilla
CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.1 [epel-6]2012-01-04
Bugzilla
CVE-2012-0287 wordpress: XSS flaw fixed in 3.3.12012-01-04
CVE-2012-0287 — Cross-site Scripting in Wordpress | cvebase