Lucene search

K
nessusTenable6883.PRM
HistoryMay 25, 2013 - 12:00 a.m.

WordPress < 3.5.2 Multiple Vulnerabilities

2013-05-2500:00:00
Tenable
www.tenable.com
15

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.02 Low

EPSS

Percentile

88.8%

Versions of WordPress earlier than 3.5.2 are potentially affected by the following vulnerabilities :

  • The application contains a denial of service attack affecting sites using password-protected posts.(CVE-2013-2173)
  • The application is affected by a server-side request forgery vulnerability. This vulnerability can be used to gain access to a site. (CVE-2013-2199)
  • A privilege escalation vulnerability exists that allows contributors to publish posts and users to reassign authorship. (CVE-2013-2200)
  • A cross-site scripting vulnerability exists related to uploading media. (CVE-2013-2201)
  • A XML External Entity Injection (XXE) vulnerability exists in β€˜oEmbed’. (CVE-2013-2202)
  • A vulnerability exists disclosing a full file path related to file upload. (CVE-2013-2203)
  • A cross-site scripting vulnerability exists related to β€˜TinyMCE’ library. (CVE-2013-2204)
  • The application is affected by a cross-site scripting vulnerability in the β€˜SWFUpload’ library. (CVE-2013-2205)
  • Cross-site scripting vulnerabilities exist in the β€˜post.php’ script relating to the β€˜excerpt’ and β€˜content’ parameters.
Binary data 6883.prm
VendorProductVersionCPE
wordpresswordpresscpe:/a:wordpress:wordpress

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.02 Low

EPSS

Percentile

88.8%