CVE-2013-0237
published 2013-07-08CVE-2013-0237: Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.14%
86.4th percentile
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Affected
91 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.5.1+dfsg-1 (bookworm) | wordpress 3.5.1+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| moxiecode | plupload | <= 1.5.4 | — |
| moxiecode | plupload | — | — |
| moxiecode | plupload | — | — |
| moxiecode | plupload | — | — |
| moxiecode | plupload | — | — |
| moxiecode | plupload | — | — |
| moxiecode | plupload | — | — |
| moxiecode | plupload | — | — |
| moxiecode | plupload | — | — |
| wordpress | wordpress | <= 3.5.0 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v2m5-2mm5-8v3w: Cross-site scripting (XSS) vulnerability in Plupload
ghsa_unreviewed·2022-05-05
CVE-2013-0237 [MEDIUM] CWE-79 GHSA-v2m5-2mm5-8v3w: Cross-site scripting (XSS) vulnerability in Plupload
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
OSV
CVE-2013-0237: Cross-site scripting (XSS) vulnerability in Plupload
osv·2013-07-08·CVSS 4.3
CVE-2013-0237 [MEDIUM] CVE-2013-0237: Cross-site scripting (XSS) vulnerability in Plupload
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Debian
CVE-2013-0237: wordpress - Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload be...
vendor_debian·2013·CVSS 4.3
CVE-2013-0237 [MEDIUM] CVE-2013-0237: wordpress - Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload be...
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Scope: local
bookworm: resolved (fixed in 3.5.1+dfsg-1)
bullseye: resolved (fixed in 3.5.1+dfsg-1)
forky: resolved (fixed in 3.5.1+dfsg-1)
sid: resolved (fixed in 3.5.1+dfsg-1)
trixie: resolved (fixed in 3.5.1+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0409 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (JMX)
bugzilla·2013-02-03·CVSS 5.0
CVE-2013-0409 [MEDIUM] CVE-2013-0409 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (JMX)
CVE-2013-0409 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (JMX)
Oracle Java SE 6 Update 39 and Java SE 7 Update 13 fix an unspecified vulnerability in the JMX component (CVE-2013-0409). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0236 https://rhn.redhat.com/er
Bugzilla
CVE-2013-1479 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (JavaFX)
bugzilla·2013-02-03·CVSS 10.0
CVE-2013-1479 [CRITICAL] CVE-2013-1479 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (JavaFX)
CVE-2013-1479 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (JavaFX)
Oracle Java SE 6 Update 39 and Java SE 7 Update 13 fix an unspecified vulnerability in the JavaFX component (CVE-2013-1479). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
Bugzilla
CVE-2013-0437 Oracle JDK: unspecified vulnerability fixed in 7u13 (2D)
bugzilla·2013-02-03·CVSS 10.0
CVE-2013-0437 [CRITICAL] CVE-2013-0437 Oracle JDK: unspecified vulnerability fixed in 7u13 (2D)
CVE-2013-0437 Oracle JDK: unspecified vulnerability fixed in 7u13 (2D)
Oracle Java SE 7 Update 13 fixes an unspecified vulnerability in the 2D component (CVE-2013-0437). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0626 https://rhn.redhat.com/errata/RHSA-2013-0626.html
Bugzilla
CVE-2013-0446 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
bugzilla·2013-02-01·CVSS 10.0
CVE-2013-0446 [CRITICAL] CVE-2013-0446 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
CVE-2013-0446 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
Java SE 6 Update 39 and Java SE 7 Update 13 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2013-0446). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0
Bugzilla
CVE-2013-0351 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
bugzilla·2013-02-01·CVSS 7.5
CVE-2013-0351 [HIGH] CVE-2013-0351 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
CVE-2013-0351 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
Java SE 6 Update 39 and Java SE 7 Update 13 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2013-0351). Upstream has CVSSv2 scored this issue as: 7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:02
Bugzilla
CVE-2012-1541 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
bugzilla·2013-02-01·CVSS 10.0
CVE-2012-1541 [CRITICAL] CVE-2012-1541 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
CVE-2012-1541 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
Java SE 6 Update 39 and Java SE 7 Update 13 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2012-1541). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0
Bugzilla
CVE-2013-0438 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
bugzilla·2013-02-01·CVSS 4.3
CVE-2013-0438 [MEDIUM] CVE-2013-0438 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
CVE-2013-0438 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
Java SE 6 Update 39 and Java SE 7 Update 13 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2013-0438). Upstream has CVSSv2 scored this issue as: 4.3/AV:N/AC:M/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:02
Bugzilla
CVE-2013-0423 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
bugzilla·2013-02-01·CVSS 7.6
CVE-2013-0423 [HIGH] CVE-2013-0423 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
CVE-2013-0423 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
Java SE 6 Update 39 and Java SE 7 Update 13 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2013-0423). Upstream has CVSSv2 scored this issue as: 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:02
Bugzilla
CVE-2013-0448 Oracle JDK: unspecified vulnerability fixed in 7u13 (Libraries)
bugzilla·2013-02-01·CVSS 5.0
CVE-2013-0448 [MEDIUM] CVE-2013-0448 Oracle JDK: unspecified vulnerability fixed in 7u13 (Libraries)
CVE-2013-0448 Oracle JDK: unspecified vulnerability fixed in 7u13 (Libraries)
Oracle Java SE 7 Update 13 fixes an unspecified vulnerability in the Libraries component (CVE-2013-0448). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
Bugzilla
CVE-2013-1473 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
bugzilla·2013-02-01·CVSS 5.0
CVE-2013-1473 [MEDIUM] CVE-2013-1473 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
CVE-2013-1473 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Deployment)
Java SE 6 Update 39 and Java SE 7 Update 13 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2013-1473). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:02
Bugzilla
CVE-2013-0445 OpenJDK: insufficient privilege checking issue (AWT, 8001057)
bugzilla·2013-02-01·CVSS 10.0
CVE-2013-0445 [CRITICAL] CVE-2013-0445 OpenJDK: insufficient privilege checking issue (AWT, 8001057)
CVE-2013-0445 OpenJDK: insufficient privilege checking issue (AWT, 8001057)
It was discovered that AWT component in the OpenJDK did not properly check privileges of the code. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
Upstream commit, as included in IcedTea7 repositories:
http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/6527ae06da69
(Includes fix for both CVE-2013-0445 (bug 906900) and CVE-2013-0442 (bug 906899))
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/
Bugzilla
CVE-2013-0430 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Install)
bugzilla·2013-02-01·CVSS 6.9
CVE-2013-0430 [MEDIUM] CVE-2013-0430 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Install)
CVE-2013-0430 Oracle JDK: unspecified vulnerability fixed in 6u39 and 7u13 (Install)
Java SE 6 Update 39 and Java SE 7 Update 13 of Oracle/Sun Java fixes an unspecified vulnerability in the Install component (CVE-2013-0430). Upstream has CVSSv2 scored this issue as: 6.9/AV:L/AC:M/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.com/errata/RHSA-2013-0237.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0236 htt
Bugzilla
CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [fedora-all]
bugzilla·2013-01-25·CVSS 6.4
CVE-2013-0235 [MEDIUM] CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [fedora-all]
CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue af
Bugzilla
CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [epel-all]
bugzilla·2013-01-25·CVSS 6.4
CVE-2013-0235 [MEDIUM] CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [epel-all]
CVE-2013-0235 CVE-2013-0236 CVE-2013-0237 wordpress various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
Bugzilla
wordpress: XSS in the external Plupload library
bugzilla·2013-01-25·CVSS 4.3
[MEDIUM] wordpress: XSS in the external Plupload library
wordpress: XSS in the external Plupload library
From WordPress upstream v3.5.1 advisory [1]:
* A cross-site scripting vulnerability in the external library Plupload. Thanks to the Moxiecode team for working with us on this, and for releasing Plupload 1.5.5 to address this issue.
References:
[1] http://wordpress.org/news/2013/01/wordpress-3-5-1/
[2] http://www.openwall.com/lists/oss-security/2013/01/25/7
Discussion:
This issue affects the versions of the wordpress package, as shipped with Fedora release of 16, 17, and 18. Please schedule an update.
--
This issue affect the versions of the wordpress package, as shipped with Fedora EPEL 5 and Fedora EPEL 6. Please schedule an update.
---
Created wordpress tracking bugs for this issue
Affects: fedora-all [bug 904124]
Affects: epel-all
http://codex.wordpress.org/Version_3.5.1http://wordpress.org/news/2013/01/wordpress-3-5-1/https://bugzilla.redhat.com/show_bug.cgi?id=904122https://github.com/moxiecode/plupload/commit/2d746ee9083c184f1234d8fed311e89bdd1b39e5http://codex.wordpress.org/Version_3.5.1http://wordpress.org/news/2013/01/wordpress-3-5-1/https://bugzilla.redhat.com/show_bug.cgi?id=904122https://github.com/moxiecode/plupload/commit/2d746ee9083c184f1234d8fed311e89bdd1b39e5
2013-07-08
Published