CVE-2012-2404
published 2012-04-21CVE-2012-2404: wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS)…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.72%
84.4th percentile
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.3.2+dfsg-1 (bookworm) | wordpress 3.3.2+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.3.1 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-grx2-xpgf-hf3r: wp-comments-post
ghsa_unreviewed·2022-05-17
CVE-2012-2404 [MEDIUM] CWE-79 GHSA-grx2-xpgf-hf3r: wp-comments-post
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
OSV
CVE-2012-2404: wp-comments-post
osv·2012-04-21·CVSS 4.3
CVE-2012-2404 [MEDIUM] CVE-2012-2404: wp-comments-post
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
Debian
CVE-2012-2404: wordpress - wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which...
vendor_debian·2012·CVSS 4.3
CVE-2012-2404 [MEDIUM] CVE-2012-2404: wordpress - wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which...
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 3.3.2+dfsg-1)
bullseye: resolved (fixed in 3.3.2+dfsg-1)
forky: resolved (fixed in 3.3.2+dfsg-1)
sid: resolved (fixed in 3.3.2+dfsg-1)
trixie: resolved (fixed in 3.3.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
bugzilla·2012-04-23·CVSS 10.0
CVE-2012-2399 [CRITICAL] CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/
Bugzilla
CVE-2012-2404 wordpress (X < v3.3.2): XSS in redirects after posting comments, and when filtering URLs
bugzilla·2012-04-23·CVSS 4.3
CVE-2012-2404 [MEDIUM] CVE-2012-2404 wordpress (X < v3.3.2): XSS in redirects after posting comments, and when filtering URLs
CVE-2012-2404 wordpress (X < v3.3.2): XSS in redirects after posting comments, and when filtering URLs
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-2404 to the following vulnerability:
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
References:
http://core.trac.wordpress.org/changeset/20486/branches/3.3/wp-comments-post.php
http://wordpress.org/news/2012/04/wordpress-3-3-2/
Discussion:
This issue affects the versions of the wordpress package, as shipped with Fedora release of 15 and 16.
--
This issue affects the versions of the wordpress package, as shipped with Fedora EPEL 5 and Fedora EPEL 6.
---
This issue is schedu
http://core.trac.wordpress.org/changeset/20486/branches/3.3/wp-comments-post.phphttp://osvdb.org/81464http://secunia.com/advisories/48957http://secunia.com/advisories/49138http://wordpress.org/news/2012/04/wordpress-3-3-2/http://www.debian.org/security/2012/dsa-2470http://www.securityfocus.com/bid/53192https://exchange.xforce.ibmcloud.com/vulnerabilities/75092https://exchange.xforce.ibmcloud.com/vulnerabilities/75202http://core.trac.wordpress.org/changeset/20486/branches/3.3/wp-comments-post.phphttp://osvdb.org/81464http://secunia.com/advisories/48957http://secunia.com/advisories/49138http://wordpress.org/news/2012/04/wordpress-3-3-2/http://www.debian.org/security/2012/dsa-2470http://www.securityfocus.com/bid/53192https://exchange.xforce.ibmcloud.com/vulnerabilities/75092https://exchange.xforce.ibmcloud.com/vulnerabilities/75202
2012-04-21
Published