CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
96.1%
Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS) vulnerability in tagcloud.swf in the WP-Cumulus Plug-in before 1.23 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter.
Vendor | Product | Version | CPE |
---|---|---|---|
roytanck | wp-cumulus | * | cpe:2.3:a:roytanck:wp-cumulus:*:*:*:*:*:*:*:* |
roytanck | wp-cumulus | 1.00 | cpe:2.3:a:roytanck:wp-cumulus:1.00:*:*:*:*:*:*:* |
roytanck | wp-cumulus | 1.01 | cpe:2.3:a:roytanck:wp-cumulus:1.01:*:*:*:*:*:*:* |
roytanck | wp-cumulus | 1.02 | cpe:2.3:a:roytanck:wp-cumulus:1.02:*:*:*:*:*:*:* |
roytanck | wp-cumulus | 1.2.1 | cpe:2.3:a:roytanck:wp-cumulus:1.2.1:*:*:*:*:*:*:* |
roytanck | wp-cumulus | 1.03 | cpe:2.3:a:roytanck:wp-cumulus:1.03:*:*:*:*:*:*:* |
roytanck | wp-cumulus | 1.04 | cpe:2.3:a:roytanck:wp-cumulus:1.04:*:*:*:*:*:*:* |
roytanck | wp-cumulus | 1.05 | cpe:2.3:a:roytanck:wp-cumulus:1.05:*:*:*:*:*:*:* |
roytanck | wp-cumulus | 1.10 | cpe:2.3:a:roytanck:wp-cumulus:1.10:*:*:*:*:*:*:* |
roytanck | wp-cumulus | 1.11 | cpe:2.3:a:roytanck:wp-cumulus:1.11:*:*:*:*:*:*:* |
packetstormsecurity.org/1001-exploits/joomlajvclouds-xss.txt
secunia.com/advisories/37483
secunia.com/advisories/38161
websecurity.com.ua/3665/
websecurity.com.ua/3789/
websecurity.com.ua/3801/
websecurity.com.ua/3839/
www.roytanck.com/2009/11/15/wp-cumulus-updated-to-address-yet-another-security-issue/
www.securityfocus.com/archive/1/508071/100/0/threaded
www.securityfocus.com/archive/1/508606/100/0/threaded
www.securityfocus.com/archive/1/508833/100/0/threaded
www.securityfocus.com/bid/37100
www.securityfocus.com/bid/37479
www.vupen.com/english/advisories/2009/3322
exchange.xforce.ibmcloud.com/vulnerabilities/54397
exchange.xforce.ibmcloud.com/vulnerabilities/55156