CVE-2013-2205
published 2013-07-08CVE-2013-2205: The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.96%
85.8th percentile
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.5.2+dfsg-1 (bookworm) | wordpress 3.5.2+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.5.1 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4vph-7h2p-5498: The default configuration of SWFUpload in WordPress before 3
ghsa_unreviewed·2022-05-17
CVE-2013-2205 [MEDIUM] CWE-79 GHSA-4vph-7h2p-5498: The default configuration of SWFUpload in WordPress before 3
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
OSV
CVE-2013-2205: The default configuration of SWFUpload in WordPress before 3
osv·2013-07-08·CVSS 4.3
CVE-2013-2205 [MEDIUM] CVE-2013-2205: The default configuration of SWFUpload in WordPress before 3
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
Debian
CVE-2013-2205: wordpress - The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestri...
vendor_debian·2013·CVSS 4.3
CVE-2013-2205 [MEDIUM] CVE-2013-2205: wordpress - The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestri...
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
Scope: local
bookworm: resolved (fixed in 3.5.2+dfsg-1)
bullseye: resolved (fixed in 3.5.2+dfsg-1)
forky: resolved (fixed in 3.5.2+dfsg-1)
sid: resolved (fixed in 3.5.2+dfsg-1)
trixie: resolved (fixed in 3.5.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version [epel-all]
bugzilla·2013-06-22·CVSS 4.3
CVE-2013-2199 [MEDIUM] CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version [epel-all]
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mentio
Bugzilla
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version [fedora-all]
bugzilla·2013-06-22·CVSS 4.3
CVE-2013-2199 [MEDIUM] CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version [fedora-all]
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention t
Bugzilla
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version
bugzilla·2013-06-21·CVSS 6.4
CVE-2013-2199 [MEDIUM] CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version
On Friday, 2013-06-21 WordPress upstream is about to release new WordPress v3.5.2 version,
correcting the following security flaws:
* CVE-2013-2199 - SSRF, multiple vulnerabilities:
Inadequate SSRF protection for HTTP requests where the user can provide a URL
can allow for attacks against the intranet and other sites. This is a
continuation of work related to CVE-2013-0235, which was specific to SSRF in
pingback requests and was fixed in 3.5.1.
* CVE-2013-2200 - Privilege escalation allowing contributors to publish posts:
Inadequate checking of a user's capabilities could allow them to publish posts
when thei
http://codex.wordpress.org/Version_3.5.2http://make.wordpress.org/core/2013/06/21/secure-swfupload/http://wordpress.org/news/2013/06/wordpress-3-5-2/http://www.debian.org/security/2013/dsa-2718http://www.securityfocus.com/bid/60759https://bugzilla.redhat.com/show_bug.cgi?id=976784http://codex.wordpress.org/Version_3.5.2http://make.wordpress.org/core/2013/06/21/secure-swfupload/http://wordpress.org/news/2013/06/wordpress-3-5-2/http://www.debian.org/security/2013/dsa-2718http://www.securityfocus.com/bid/60759https://bugzilla.redhat.com/show_bug.cgi?id=976784
2013-07-08
Published