CVE-2012-2399
published 2012-04-21CVE-2012-2399: Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.68%
94.5th percentile
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.3.2+dfsg-1 (bookworm) | wordpress 3.3.2+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.3.1 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m6ch-qxrg-ggw6: Cross-site scripting (XSS) vulnerability in swfupload
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2012-2399 [MEDIUM] GHSA-m6ch-qxrg-ggw6: Cross-site scripting (XSS) vulnerability in swfupload
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.
OSV
CVE-2012-2399: Cross-site scripting (XSS) vulnerability in swfupload
osv·2012-04-21·CVSS 10.0
CVE-2012-2399 [CRITICAL] CVE-2012-2399: Cross-site scripting (XSS) vulnerability in swfupload
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.
Debian
CVE-2012-2399: wordpress - Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 a...
vendor_debian·2012·CVSS 10.0
CVE-2012-2399 [CRITICAL] CVE-2012-2399: wordpress - Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 a...
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.
Scope: local
bookworm: resolved (fixed in 3.3.2+dfsg-1)
bullseye: resolved (fixed in 3.3.2+dfsg-1)
forky: resolved (fixed in 3.3.2+dfsg-1)
sid: resolved (fixed in 3.3.2+dfsg-1)
trixie: resolved (fixed in 3.3.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
hacks.mozilla.org - SWFUpload Vulnerable Version
bugzilla·2012-05-02·CVSS 10.0
[CRITICAL] hacks.mozilla.org - SWFUpload Vulnerable Version
hacks.mozilla.org - SWFUpload Vulnerable Version
User Agent: Mozilla/5.0 (Windows NT 5.1; rv:10.0) Gecko/20100101 Firefox/10.0
Build ID: 20120129021758
Steps to reproduce:
Hello,
I wanna to report a bug in site mpl.mozilla.org (Wordpress 3.3.1).
About bug we can read, for example here:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=0
Actual results:
Location of vulnerable:
http://hacks.mozilla.org/wp-includes/js/swfupload/swfupload.swf
---
Impact Type:Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service
---
Expected results:
For fix this vulnerability script must be updated for Wordpress 3.3.2
Discussion:
This is a working link for nist.gov:
http://web.nvd.nist.gov/view/vuln/detail? vulnId=CVE-2012-2399
Btw. Does thi
Bugzilla
[XSS] air.mozilla.org - SWFUpload Vulnerable Version
bugzilla·2012-05-02·CVSS 10.0
[CRITICAL] [XSS] air.mozilla.org - SWFUpload Vulnerable Version
[XSS] air.mozilla.org - SWFUpload Vulnerable Version
User Agent: Mozilla/5.0 (Windows NT 5.1; rv:10.0) Gecko/20100101 Firefox/10.0
Build ID: 20120129021758
Steps to reproduce:
Hello,
I wanna to report a bug in site air.mozilla.org (Wordpress 3.3.1).
About bug we can read, for example here:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=0
Actual results:
Actual results:
Location of vulnerable:
https://air.mozilla.org/wp-includes/js/swfupload/swfupload.swf
---
Impact Type:Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service
---
Expected results:
For fix this vulnerability script must be updated for Wordpress 3.3.2
Discussion:
Your link to nist.gov doesn't work.
Air Mozilla should be upgraded soon though.
---
This is a
Bugzilla
CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
bugzilla·2012-04-23·CVSS 10.0
CVE-2012-2399 [CRITICAL] CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/
Bugzilla
CVE-2012-2399 wordpress (X < 3.3.2): Unspecified vulnerability in SWFUpload
bugzilla·2012-04-23·CVSS 10.0
CVE-2012-2399 [CRITICAL] CVE-2012-2399 wordpress (X < 3.3.2): Unspecified vulnerability in SWFUpload
CVE-2012-2399 wordpress (X < 3.3.2): Unspecified vulnerability in SWFUpload
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-2399 to the following vulnerability:
Unspecified vulnerability in wp-includes/js/swfupload/swfupload.swf in WordPress before 3.3.2 has unknown impact and attack vectors.
References:
http://wordpress.org/news/2012/04/wordpress-3-3-2/
http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/swfupload/swfupload.swf?rev=20503
Discussion:
This issue affects the versions of the wordpress package, as shipped with Fedora release of 15 and 16.
--
This issue affects the versions of the wordpress package, as shipped with Fedora EPEL 5 and Fedora EPEL 6.
---
This issue is scheduled to be corrected via the following updates:
1) wordpress-3.3
CTF
headquarters / Exposure-L11C10
ctf_writeups·2024·CVSS 10.0
[CRITICAL] headquarters / Exposure-L11C10
# 💣 Exposure - L11 C10
One of the Bulldogs, Lara Mindsay, is a surveillance expert and we think she's been using advanced drones to take high resolution photos of the bank from different angles.
She also runs a small legit side project, a photo site which allows anyone to create an account and upload photos. We think she's using it herself to store the bank surveillance photos and so we want to see if it's vulnerable. We've been penetration testing the site but have not had any success so far, then this morning one of the other agents sent me a tip - CVE-2012-2399. Take a look and see if you can use it to see if the site is vulnerable.
**Tip:** Find the vulnerability to get the flag.
## Need a hint?
> 💡 Hint: What does google say about the CVE? Are there examples of ways to take adva
http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/swfupload/swfupload.swf?rev=20503http://jvn.jp/en/jp/JVN25280162/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2012-002110http://make.wordpress.org/core/2013/06/21/secure-swfupload/http://osvdb.org/81459http://packetstormsecurity.com/files/120746/SWFUpload-Content-Spoofing-Cross-Site-Scripting.htmlhttp://packetstormsecurity.com/files/122399/tinymce11-xss.txthttp://seclists.org/fulldisclosure/2013/Mar/110http://secunia.com/advisories/49138http://wordpress.org/news/2012/04/wordpress-3-3-2/http://www.debian.org/security/2012/dsa-2470http://www.openwall.com/lists/oss-security/2013/07/18/13http://www.osvdb.org/91134http://www.securityfocus.com/bid/53192https://exchange.xforce.ibmcloud.com/vulnerabilities/75210http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/swfupload/swfupload.swf?rev=20503http://jvn.jp/en/jp/JVN25280162/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2012-002110http://make.wordpress.org/core/2013/06/21/secure-swfupload/http://osvdb.org/81459http://packetstormsecurity.com/files/120746/SWFUpload-Content-Spoofing-Cross-Site-Scripting.htmlhttp://packetstormsecurity.com/files/122399/tinymce11-xss.txthttp://seclists.org/fulldisclosure/2013/Mar/110http://secunia.com/advisories/49138http://wordpress.org/news/2012/04/wordpress-3-3-2/http://www.debian.org/security/2012/dsa-2470http://www.openwall.com/lists/oss-security/2013/07/18/13http://www.osvdb.org/91134http://www.securityfocus.com/bid/53192https://exchange.xforce.ibmcloud.com/vulnerabilities/75210
2012-04-21
Published