CVE Vulnerabilities

CVE-2012-2399

Published: Apr 21, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress*3.3.1 (including)
WordpressWordpress0.71 (including)0.71 (including)
WordpressWordpress1.0 (including)1.0 (including)
WordpressWordpress1.0.1 (including)1.0.1 (including)
WordpressWordpress1.0.2 (including)1.0.2 (including)
WordpressWordpress1.1.1 (including)1.1.1 (including)
WordpressWordpress1.2 (including)1.2 (including)
WordpressWordpress1.2.1 (including)1.2.1 (including)
WordpressWordpress1.2.2 (including)1.2.2 (including)
WordpressWordpress1.2.3 (including)1.2.3 (including)
WordpressWordpress1.2.4 (including)1.2.4 (including)
WordpressWordpress1.2.5 (including)1.2.5 (including)
WordpressWordpress1.2.5-a (including)1.2.5-a (including)
WordpressWordpress1.3 (including)1.3 (including)
WordpressWordpress1.3.2 (including)1.3.2 (including)
WordpressWordpress1.3.3 (including)1.3.3 (including)
WordpressWordpress1.5 (including)1.5 (including)
WordpressWordpress1.5.1 (including)1.5.1 (including)
WordpressWordpress1.5.1.1 (including)1.5.1.1 (including)
WordpressWordpress1.5.1.2 (including)1.5.1.2 (including)
WordpressWordpress1.5.1.3 (including)1.5.1.3 (including)
WordpressWordpress1.5.2 (including)1.5.2 (including)
WordpressWordpress2.0 (including)2.0 (including)
WordpressWordpress2.0.1 (including)2.0.1 (including)
WordpressWordpress2.0.2 (including)2.0.2 (including)
WordpressWordpress2.0.4 (including)2.0.4 (including)
WordpressWordpress2.0.5 (including)2.0.5 (including)
WordpressWordpress2.0.6 (including)2.0.6 (including)
WordpressWordpress2.0.7 (including)2.0.7 (including)
WordpressWordpress2.0.8 (including)2.0.8 (including)
WordpressWordpress2.0.9 (including)2.0.9 (including)
WordpressWordpress2.0.10 (including)2.0.10 (including)
WordpressWordpress2.0.11 (including)2.0.11 (including)
WordpressWordpress2.1 (including)2.1 (including)
WordpressWordpress2.1.1 (including)2.1.1 (including)
WordpressWordpress2.1.2 (including)2.1.2 (including)
WordpressWordpress2.1.3 (including)2.1.3 (including)
WordpressWordpress2.2 (including)2.2 (including)
WordpressWordpress2.2.1 (including)2.2.1 (including)
WordpressWordpress2.2.2 (including)2.2.2 (including)
WordpressWordpress2.2.3 (including)2.2.3 (including)
WordpressWordpress2.3 (including)2.3 (including)
WordpressWordpress2.3.1 (including)2.3.1 (including)
WordpressWordpress2.3.2 (including)2.3.2 (including)
WordpressWordpress2.3.3 (including)2.3.3 (including)
WordpressWordpress2.5 (including)2.5 (including)
WordpressWordpress2.5.1 (including)2.5.1 (including)
WordpressWordpress2.6 (including)2.6 (including)
WordpressWordpress2.6.1 (including)2.6.1 (including)
WordpressWordpress2.6.2 (including)2.6.2 (including)
WordpressWordpress2.6.3 (including)2.6.3 (including)
WordpressWordpress2.6.5 (including)2.6.5 (including)
WordpressWordpress2.7 (including)2.7 (including)
WordpressWordpress2.7.1 (including)2.7.1 (including)
WordpressWordpress2.8 (including)2.8 (including)
WordpressWordpress2.8.1 (including)2.8.1 (including)
WordpressWordpress2.8.2 (including)2.8.2 (including)
WordpressWordpress2.8.3 (including)2.8.3 (including)
WordpressWordpress2.8.4 (including)2.8.4 (including)
WordpressWordpress2.8.4-a (including)2.8.4-a (including)
WordpressWordpress2.8.5 (including)2.8.5 (including)
WordpressWordpress2.8.5.1 (including)2.8.5.1 (including)
WordpressWordpress2.8.5.2 (including)2.8.5.2 (including)
WordpressWordpress2.8.6 (including)2.8.6 (including)
WordpressWordpress2.9 (including)2.9 (including)
WordpressWordpress2.9.1 (including)2.9.1 (including)
WordpressWordpress2.9.1.1 (including)2.9.1.1 (including)
WordpressWordpress2.9.2 (including)2.9.2 (including)
WordpressWordpress3.0 (including)3.0 (including)
WordpressWordpress3.0.1 (including)3.0.1 (including)
WordpressWordpress3.0.2 (including)3.0.2 (including)
WordpressWordpress3.0.3 (including)3.0.3 (including)
WordpressWordpress3.0.4 (including)3.0.4 (including)
WordpressWordpress3.0.5 (including)3.0.5 (including)
WordpressWordpress3.0.6 (including)3.0.6 (including)
WordpressWordpress3.1 (including)3.1 (including)
WordpressWordpress3.1.1 (including)3.1.1 (including)
WordpressWordpress3.1.2 (including)3.1.2 (including)
WordpressWordpress3.1.3 (including)3.1.3 (including)
WordpressWordpress3.3 (including)3.3 (including)
WordpressUbuntuhardy*
WordpressUbuntulucid*
WordpressUbuntunatty*
WordpressUbuntuoneiric*
WordpressUbuntuprecise*
WordpressUbuntuupstream*

References