Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.71272
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: wordpress
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: wordpress

CVE-2012-2399
Unspecified vulnerability in wp-includes/js/swfupload/swfupload.swf in
WordPress before 3.3.2 has unknown impact and attack vectors.
CVE-2012-2400
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress
before 3.3.2 has unknown impact and attack vectors.
CVE-2012-2401
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in
WordPress before 3.3.2 and other products, enables scripting
regardless of the domain from which the SWF content was loaded, which
allows remote attackers to bypass the Same Origin Policy via crafted
content.
CVE-2012-2402
wp-admin/plugins.php in WordPress before 3.3.2 allows remote
authenticated site administrators to bypass intended access
restrictions and deactivate network-wide plugins via unspecified
vectors.
CVE-2012-2403
wp-includes/formatting.php in WordPress before 3.3.2 attempts to
enable clickable links inside attributes, which makes it easier for
remote attackers to conduct cross-site scripting (XSS) attacks via
unspecified vectors.
CVE-2012-2404
wp-comments-post.php in WordPress before 3.3.2 supports offsite
redirects, which makes it easier for remote attackers to conduct
cross-site scripting (XSS) attacks via unspecified vectors.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2012-2399
BugTraq ID: 53192
http://www.securityfocus.com/bid/53192
Debian Security Information: DSA-2470 (Google Search)
http://www.debian.org/security/2012/dsa-2470
http://seclists.org/fulldisclosure/2013/Mar/110
http://jvn.jp/en/jp/JVN25280162/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2012-002110
http://packetstormsecurity.com/files/120746/SWFUpload-Content-Spoofing-Cross-Site-Scripting.html
http://packetstormsecurity.com/files/122399/tinymce11-xss.txt
http://www.openwall.com/lists/oss-security/2013/07/18/13
http://osvdb.org/81459
http://www.osvdb.org/91134
http://secunia.com/advisories/49138
XForce ISS Database: wordpress-swfupload-unspecified(75210)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75210
Common Vulnerability Exposure (CVE) ID: CVE-2012-2400
http://osvdb.org/81460
XForce ISS Database: wordpress-swfobject-unspecified(75209)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75209
Common Vulnerability Exposure (CVE) ID: CVE-2012-2401
https://nealpoole.com/blog/2012/05/xss-and-csrf-via-swf-applets-swfupload-plupload/
http://osvdb.org/81461
XForce ISS Database: wordpress-plupload-sec-bypass(75208)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75208
Common Vulnerability Exposure (CVE) ID: CVE-2012-2402
http://osvdb.org/81462
http://secunia.com/advisories/48957
XForce ISS Database: wordpress-plugins-sec-bypass(75207)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75207
XForce ISS Database: wordpress-plugins-security-bypass(75090)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75090
Common Vulnerability Exposure (CVE) ID: CVE-2012-2403
http://osvdb.org/81463
XForce ISS Database: wordpress-formatting-xss(75206)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75206
XForce ISS Database: wordpress-url-xss(75093)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75093
Common Vulnerability Exposure (CVE) ID: CVE-2012-2404
http://osvdb.org/81464
XForce ISS Database: wordpress-wpcommentspostphp-xss(75202)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75202
XForce ISS Database: wordpress-wpredirect-xss(75092)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75092
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.