CVE Vulnerabilities

CVE-2012-2401

Published: Apr 21, 2012 | Modified: Dec 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.

Affected Software

Name Vendor Start Version End Version
Plupload Moxiecode * 1.5.3 (including)
Plupload Moxiecode 1.4.0 (including) 1.4.0 (including)
Plupload Moxiecode 1.4.1 (including) 1.4.1 (including)
Plupload Moxiecode 1.4.2 (including) 1.4.2 (including)
Plupload Moxiecode 1.4.3 (including) 1.4.3 (including)
Plupload Moxiecode 1.5.0 (including) 1.5.0 (including)
Plupload Moxiecode 1.5.0-beta (including) 1.5.0-beta (including)
Plupload Moxiecode 1.5.1 (including) 1.5.1 (including)
Plupload Moxiecode 1.5.2 (including) 1.5.2 (including)
Wordpress Wordpress * 3.3.1 (including)
Wordpress Wordpress 0.71 (including) 0.71 (including)
Wordpress Wordpress 1.0 (including) 1.0 (including)
Wordpress Wordpress 1.0.1 (including) 1.0.1 (including)
Wordpress Wordpress 1.0.2 (including) 1.0.2 (including)
Wordpress Wordpress 1.1.1 (including) 1.1.1 (including)
Wordpress Wordpress 1.2 (including) 1.2 (including)
Wordpress Wordpress 1.2.1 (including) 1.2.1 (including)
Wordpress Wordpress 1.2.2 (including) 1.2.2 (including)
Wordpress Wordpress 1.2.3 (including) 1.2.3 (including)
Wordpress Wordpress 1.2.4 (including) 1.2.4 (including)
Wordpress Wordpress 1.2.5 (including) 1.2.5 (including)
Wordpress Wordpress 1.2.5-a (including) 1.2.5-a (including)
Wordpress Wordpress 1.3 (including) 1.3 (including)
Wordpress Wordpress 1.3.2 (including) 1.3.2 (including)
Wordpress Wordpress 1.3.3 (including) 1.3.3 (including)
Wordpress Wordpress 1.5 (including) 1.5 (including)
Wordpress Wordpress 1.5.1 (including) 1.5.1 (including)
Wordpress Wordpress 1.5.1.1 (including) 1.5.1.1 (including)
Wordpress Wordpress 1.5.1.2 (including) 1.5.1.2 (including)
Wordpress Wordpress 1.5.1.3 (including) 1.5.1.3 (including)
Wordpress Wordpress 1.5.2 (including) 1.5.2 (including)
Wordpress Wordpress 2.0 (including) 2.0 (including)
Wordpress Wordpress 2.0.1 (including) 2.0.1 (including)
Wordpress Wordpress 2.0.2 (including) 2.0.2 (including)
Wordpress Wordpress 2.0.4 (including) 2.0.4 (including)
Wordpress Wordpress 2.0.5 (including) 2.0.5 (including)
Wordpress Wordpress 2.0.6 (including) 2.0.6 (including)
Wordpress Wordpress 2.0.7 (including) 2.0.7 (including)
Wordpress Wordpress 2.0.8 (including) 2.0.8 (including)
Wordpress Wordpress 2.0.9 (including) 2.0.9 (including)
Wordpress Wordpress 2.0.10 (including) 2.0.10 (including)
Wordpress Wordpress 2.0.11 (including) 2.0.11 (including)
Wordpress Wordpress 2.1 (including) 2.1 (including)
Wordpress Wordpress 2.1.1 (including) 2.1.1 (including)
Wordpress Wordpress 2.1.2 (including) 2.1.2 (including)
Wordpress Wordpress 2.1.3 (including) 2.1.3 (including)
Wordpress Wordpress 2.2 (including) 2.2 (including)
Wordpress Wordpress 2.2.1 (including) 2.2.1 (including)
Wordpress Wordpress 2.2.2 (including) 2.2.2 (including)
Wordpress Wordpress 2.2.3 (including) 2.2.3 (including)
Wordpress Wordpress 2.3 (including) 2.3 (including)
Wordpress Wordpress 2.3.1 (including) 2.3.1 (including)
Wordpress Wordpress 2.3.2 (including) 2.3.2 (including)
Wordpress Wordpress 2.3.3 (including) 2.3.3 (including)
Wordpress Wordpress 2.5 (including) 2.5 (including)
Wordpress Wordpress 2.5.1 (including) 2.5.1 (including)
Wordpress Wordpress 2.6 (including) 2.6 (including)
Wordpress Wordpress 2.6.1 (including) 2.6.1 (including)
Wordpress Wordpress 2.6.2 (including) 2.6.2 (including)
Wordpress Wordpress 2.6.3 (including) 2.6.3 (including)
Wordpress Wordpress 2.6.5 (including) 2.6.5 (including)
Wordpress Wordpress 2.7 (including) 2.7 (including)
Wordpress Wordpress 2.7.1 (including) 2.7.1 (including)
Wordpress Wordpress 2.8 (including) 2.8 (including)
Wordpress Wordpress 2.8.1 (including) 2.8.1 (including)
Wordpress Wordpress 2.8.2 (including) 2.8.2 (including)
Wordpress Wordpress 2.8.3 (including) 2.8.3 (including)
Wordpress Wordpress 2.8.4 (including) 2.8.4 (including)
Wordpress Wordpress 2.8.4-a (including) 2.8.4-a (including)
Wordpress Wordpress 2.8.5 (including) 2.8.5 (including)
Wordpress Wordpress 2.8.5.1 (including) 2.8.5.1 (including)
Wordpress Wordpress 2.8.5.2 (including) 2.8.5.2 (including)
Wordpress Wordpress 2.8.6 (including) 2.8.6 (including)
Wordpress Wordpress 2.9 (including) 2.9 (including)
Wordpress Wordpress 2.9.1 (including) 2.9.1 (including)
Wordpress Wordpress 2.9.1.1 (including) 2.9.1.1 (including)
Wordpress Wordpress 2.9.2 (including) 2.9.2 (including)
Wordpress Wordpress 3.0 (including) 3.0 (including)
Wordpress Wordpress 3.0.1 (including) 3.0.1 (including)
Wordpress Wordpress 3.0.2 (including) 3.0.2 (including)
Wordpress Wordpress 3.0.3 (including) 3.0.3 (including)
Wordpress Wordpress 3.0.4 (including) 3.0.4 (including)
Wordpress Wordpress 3.0.5 (including) 3.0.5 (including)
Wordpress Wordpress 3.0.6 (including) 3.0.6 (including)
Wordpress Wordpress 3.1 (including) 3.1 (including)
Wordpress Wordpress 3.1.1 (including) 3.1.1 (including)
Wordpress Wordpress 3.1.2 (including) 3.1.2 (including)
Wordpress Wordpress 3.1.3 (including) 3.1.3 (including)
Wordpress Wordpress 3.3 (including) 3.3 (including)
Wordpress Ubuntu hardy *
Wordpress Ubuntu lucid *
Wordpress Ubuntu natty *
Wordpress Ubuntu oneiric *
Wordpress Ubuntu precise *
Wordpress Ubuntu upstream *

References