CVE-2012-2400
published 2012-04-21CVE-2012-2400: Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
PriorityP433critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.06%
86.1th percentile
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.3.2+dfsg-1 (bookworm) | wordpress 3.3.2+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.3.1 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8p43-h625-cvh5: Unspecified vulnerability in wp-includes/js/swfobject
ghsa_unreviewed·2022-05-17
CVE-2012-2400 [HIGH] GHSA-8p43-h625-cvh5: Unspecified vulnerability in wp-includes/js/swfobject
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
OSV
CVE-2012-2400: Unspecified vulnerability in wp-includes/js/swfobject
osv·2012-04-21·CVSS 10.0
CVE-2012-2400 [CRITICAL] CVE-2012-2400: Unspecified vulnerability in wp-includes/js/swfobject
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
Debian
CVE-2012-2400: wordpress - Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3...
vendor_debian·2012·CVSS 10.0
CVE-2012-2400 [CRITICAL] CVE-2012-2400: wordpress - Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3...
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
Scope: local
bookworm: resolved (fixed in 3.3.2+dfsg-1)
bullseye: resolved (fixed in 3.3.2+dfsg-1)
forky: resolved (fixed in 3.3.2+dfsg-1)
sid: resolved (fixed in 3.3.2+dfsg-1)
trixie: resolved (fixed in 3.3.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
bugzilla·2012-04-23·CVSS 10.0
CVE-2012-2399 [CRITICAL] CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/
Bugzilla
CVE-2012-2400 wordpress (X < v3.3.2): Unspecified vulnerability in the SWFObject
bugzilla·2012-04-23·CVSS 10.0
CVE-2012-2400 [CRITICAL] CVE-2012-2400 wordpress (X < v3.3.2): Unspecified vulnerability in the SWFObject
CVE-2012-2400 wordpress (X < v3.3.2): Unspecified vulnerability in the SWFObject
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-2400 to the following vulnerability:
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
References:
http://core.trac.wordpress.org/changeset/20499/branches/3.3/wp-includes/js/swfobject.js
http://wordpress.org/news/2012/04/wordpress-3-3-2/
Discussion:
This issue affects the versions of the wordpress package, as shipped with Fedora release of 15 and 16.
--
This issue affects the versions of the wordpress package, as shipped with Fedora EPEL 5 and Fedora EPEL 6.
---
This issue is scheduled to be corrected via the following updates:
1) wordpress-3.3.2-2.el6 for Fedora
http://core.trac.wordpress.org/changeset/20499/branches/3.3/wp-includes/js/swfobject.jshttp://osvdb.org/81460http://secunia.com/advisories/49138http://wordpress.org/news/2012/04/wordpress-3-3-2/http://www.debian.org/security/2012/dsa-2470http://www.securityfocus.com/bid/53192https://exchange.xforce.ibmcloud.com/vulnerabilities/75209http://core.trac.wordpress.org/changeset/20499/branches/3.3/wp-includes/js/swfobject.jshttp://osvdb.org/81460http://secunia.com/advisories/49138http://wordpress.org/news/2012/04/wordpress-3-3-2/http://www.debian.org/security/2012/dsa-2470http://www.securityfocus.com/bid/53192https://exchange.xforce.ibmcloud.com/vulnerabilities/75209
2012-04-21
Published