Lucene search

K
cvelistRedhatCVELIST:CVE-2013-2205
HistoryJul 08, 2013 - 8:00 p.m.

CVE-2013-2205

2013-07-0820:00:00
redhat
www.cve.org

5.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.5%

The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.

5.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.5%