CVE-2013-0236
published 2013-07-08CVE-2013-0236: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.48%
82.8th percentile
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.5.1+dfsg-1 (bookworm) | wordpress 3.5.1+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.5.0 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wwqr-4v22-f2qm: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3
ghsa_unreviewed·2022-05-05
CVE-2013-0236 [MEDIUM] CWE-79 GHSA-wwqr-4v22-f2qm: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
OSV
CVE-2013-0236: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3
osv·2013-07-08·CVSS 4.3
CVE-2013-0236 [MEDIUM] CVE-2013-0236: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
Debian
CVE-2013-0236: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 al...
vendor_debian·2013·CVSS 4.3
CVE-2013-0236 [MEDIUM] CVE-2013-0236: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 al...
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
Scope: local
bookworm: resolved (fixed in 3.5.1+dfsg-1)
bullseye: resolved (fixed in 3.5.1+dfsg-1)
forky: resolved (fixed in 3.5.1+dfsg-1)
sid: resolved (fixed in 3.5.1+dfsg-1)
trixie: resolved (fixed in 3.5.1+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0409 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (JMX)
bugzilla·2013-02-03·CVSS 5.0
CVE-2013-0409 [MEDIUM] CVE-2013-0409 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (JMX)
CVE-2013-0409 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (JMX)
Oracle Java SE 6 Update 39 and Java SE 7 Update 13 fix an unspecified vulnerability in the JMX component (CVE-2013-0409). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0236 https://rhn.redhat.com/er
Bugzilla
CVE-2013-1481 Oracle JDK: unspecified vulnerability fixed in 6u39 (Sound)
bugzilla·2013-02-03·CVSS 10.0
CVE-2013-1481 [CRITICAL] CVE-2013-1481 Oracle JDK: unspecified vulnerability fixed in 6u39 (Sound)
CVE-2013-1481 Oracle JDK: unspecified vulnerability fixed in 6u39 (Sound)
Oracle Java SE 6 Update 39 fixes an unspecified vulnerability in the Sound component (CVE-2013-1481). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0236 https://rhn.redhat.com/errata/RHSA-2013-0236.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0624 https://rhn.redhat.com/errata/RHSA-2013-0624.html
Bugzilla
CVE-2012-3213 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Scripting)
bugzilla·2013-02-03·CVSS 10.0
CVE-2012-3213 [CRITICAL] CVE-2012-3213 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Scripting)
CVE-2012-3213 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Scripting)
Oracle Java SE 6 Update 39 and Java SE 7 Update 13 fix an unspecified vulnerability in the Scripting component (CVE-2012-3213). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0236 https://rhn.
Bugzilla
CVE-2013-0430 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Install)
bugzilla·2013-02-01·CVSS 6.9
CVE-2013-0430 [MEDIUM] CVE-2013-0430 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Install)
CVE-2013-0430 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Install)
Java SE 6 Update 39 and Java SE 7 Update 13 of Oracle/Sun Java fixes an unspecified vulnerability in the Install component (CVE-2013-0430). Upstream has CVSSv2 scored this issue as: 6.9/AV:L/AC:M/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0236 htt
Bugzilla
CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [fedora-all]
bugzilla·2013-01-25·CVSS 6.4
CVE-2013-0235 [MEDIUM] CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [fedora-all]
CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue af
Bugzilla
CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [epel-all]
bugzilla·2013-01-25·CVSS 6.4
CVE-2013-0235 [MEDIUM] CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [epel-all]
CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
Bugzilla
wordpress: XSS flaws via shortcodes and HTTP POST content
bugzilla·2013-01-25·CVSS 4.3
[MEDIUM] wordpress: XSS flaws via shortcodes and HTTP POST content
wordpress: XSS flaws via shortcodes and HTTP POST content
From WordPress upstream v3.5.1 advisory [1]:
* Two instances of cross-site scripting via shortcodes and post content. These issues were discovered by Jon Cave of the WordPress security team.
References:
[1] http://wordpress.org/news/2013/01/wordpress-3-5-1/
[2] http://www.openwall.com/lists/oss-security/2013/01/25/7
Discussion:
This issue affects the versions of the wordpress package, as shipped with Fedora release of 16, 17, and 18. Please schedule an update.
--
This issue affect the versions of the wordpress package, as shipped with Fedora EPEL 5 and Fedora EPEL 6. Please schedule an update.
---
Created wordpress tracking bugs for this issue
Affects: fedora-all [bug 904124]
Affects: epel-all [bug 904125]
---
The CVE ide
http://codex.wordpress.org/Version_3.5.1http://core.trac.wordpress.org/changeset/23317http://core.trac.wordpress.org/changeset/23322http://wordpress.org/news/2013/01/wordpress-3-5-1/https://bugzilla.redhat.com/show_bug.cgi?id=904121http://codex.wordpress.org/Version_3.5.1http://core.trac.wordpress.org/changeset/23317http://core.trac.wordpress.org/changeset/23322http://wordpress.org/news/2013/01/wordpress-3-5-1/https://bugzilla.redhat.com/show_bug.cgi?id=904121
2013-07-08
Published