Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-0782

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2012-0782
Last Modified 31 Jan 2012 09:01:05
Published 30 Jan 2012 12:55:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-0782

Summary

** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether this specific XSS scenario has security relevance.

Vulnerable Systems

Application

  • Wordpress 0.7

  • Wordpress 0.71

  • Wordpress 0.711

  • Wordpress 0.72

  • Wordpress 1.0

  • Wordpress 1.0.1

  • Wordpress 1.0.2

  • Wordpress 1.2

  • Wordpress 1.2.1

  • Wordpress 1.2.2

  • Wordpress 1.5

  • Wordpress 1.5.1

  • Wordpress 1.5.1.2

  • Wordpress 1.5.1.3

  • Wordpress 1.5.2

  • Wordpress 2.0

  • Wordpress 2.0.1

  • Wordpress 2.0.10

  • Wordpress 2.0.11

  • Wordpress 2.0.2

  • Wordpress 2.0.3

  • Wordpress 2.0.4

  • Wordpress 2.0.5

  • Wordpress 2.0.6

  • Wordpress 2.0.7

  • Wordpress 2.0.8

  • Wordpress 2.0.9

  • Wordpress 2.1

  • Wordpress 2.1.1

  • Wordpress 2.1.2

  • Wordpress 2.1.3

  • Wordpress 2.2

  • Wordpress 2.2.1

  • Wordpress 2.2.2

  • Wordpress 2.2.3

  • Wordpress 2.3

  • Wordpress 2.3.1

  • Wordpress 2.3.2

  • Wordpress 2.3.3

  • Wordpress 2.5

  • Wordpress 2.5.1

  • Wordpress 2.6

  • Wordpress 2.6.1

  • Wordpress 2.6.2

  • Wordpress 2.6.3

  • Wordpress 2.6.5

  • Wordpress 2.7

  • Wordpress 2.7.1

  • Wordpress 2.8

  • Wordpress 2.8.1

  • Wordpress 2.8.2

  • Wordpress 2.8.3

  • Wordpress 2.8.4

  • Wordpress 2.8.5

  • Wordpress 2.8.6

  • Wordpress 2.9

  • Wordpress 2.9.1

  • Wordpress 2.9.2

  • Wordpress 3.0

  • Wordpress 3.0.1

  • Wordpress 3.0.2

  • Wordpress 3.0.3

  • Wordpress 3.0.4

  • Wordpress 3.0.5

  • Wordpress 3.0.6

  • Wordpress 3.1

  • Wordpress 3.1.1

  • Wordpress 3.1.2

  • Wordpress 3.1.3

  • Wordpress 3.1.4

  • Wordpress 3.2.1

  • Wordpress 3.3

  • Wordpress 3.3.1


References

MISC - https://www.trustwave.com/spiderlabs/advisories/TWSL2012-002.txt

EXPLOIT-DB - 18417

BUGTRAQ - 20120124 TWSL2012-002: Multiple Vulnerabilities in WordPress


Last Updated: 27 May 2016 10:58:08