CVE-2012-3414

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Im… (CVE-2012-3414)

Description

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

Source: CVELISTV5NVD

Metrics

Severity
none
no public PoC known
95.0 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
9.1 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2013-07-19 10:00 UTC

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • swfupload_project

    swfupload2.2.0.1

  • swfupload_project

    swfupload

  • tinymce

    image_manager

  • wordpress

    wordpress3.3.1

  • wordpress

    wordpress

References & sources

IDCVE-2012-3414