CVE-2013-2204Improper Input Validation in Wordpress

Severity
4.3MEDIUMNVD
EPSS
0.7%
top 28.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 8
Latest updateMay 17

Description

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/wordpress< wordpress 3.5.2+dfsg-1 (bookworm)
Debianwordpress/wordpress< 3.5.2+dfsg-1+3
NVDwordpress/wordpress3.5.1+74

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qm3h-34vf-g6fh: moxieplayer2022-05-17
OSV
CVE-2013-2204: moxieplayer2013-07-08

📋Vendor Advisories

2
Red Hat
tomcat: World-readable log directory2013-02-22
Debian
CVE-2013-2204: wordpress - moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in ...2013

💬Community

3
Bugzilla
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version [epel-all]2013-06-22
Bugzilla
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version [fedora-all]2013-06-22
Bugzilla
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version2013-06-21
CVE-2013-2204 — Improper Input Validation in Wordpress | cvebase