CVE-2012-4273 – 2 Click Social Media Buttons < 0.34 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-4273
Cross-site scripting (XSS) vulnerability in libs/xing.php in the 2 Click Social Media Buttons plugin before 0.34 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xing-url parameter. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en libs/xing.php en el plugin '2 Click Social Media Buttons' antes de v0.34 para WordPress permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro xing-url. • http://packetstormsecurity.org/files/112615/WordPress-2-Click-Socialmedia-Buttons-Cross-Site-Scripting.html http://plugins.trac.wordpress.org/changeset?old_path=%2F2-click-socialmedia-buttons&old=532798&new_path=%2F2-click-socialmedia-buttons&new=532798 http://wordpress.org/extend/plugins/2-click-socialmedia-buttons/changelog https://exchange.xforce.ibmcloud.com/vulnerabilities/75518 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-4264 – Better WP Security <= 3.2.4 - Multiple Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-4264
Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en el plugin 'Better WP Security' (better_wp_security) para WordPress antes de v3.2.5 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados relacionados con "variables de servidor". Se trata una vulnerabilidad diferente a CVE-2012-4263. • http://bit51.com/software/better-wp-security/changelog http://plugins.trac.wordpress.org/changeset?old_path=%2Fbetter-wp-security&old=542852&new_path=%2Fbetter-wp-security&new=542852 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-4271 – Bad Behavior < 2.0.47 & 2.2.0 - 2.2.4 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-4271
Multiple cross-site scripting (XSS) vulnerabilities in bad-behavior-wordpress-admin.php in the Bad Behavior plugin before 2.0.47 and 2.2.x before 2.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) httpbl_key, (3) httpbl_maxage, (4) httpbl_threat, (5) reverse_proxy_addresses, or (6) reverse_proxy_header parameter. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en bad-behavior-wordpress-admin.php en el plugin 'Bad Behavior' (mala conducta) antes de v2.0.47 y v2.2.x antes de v2.2.5 para WordPress permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) PATH_INFO, (2) httpbl_key, (3) httpbl_maxage, (4) httpbl_threat, (5) reverse_proxy_addresses, o (6) el parámetro reverse_proxy_header. • http://packetstormsecurity.org/files/112619/WordPress-Bad-Behavior-Cross-Site-Scripting.html http://plugins.trac.wordpress.org/changeset?old_path=%2Fbad-behavior&old=543807&new_path=%2Fbad-behavior&new=543807 http://www.securityfocus.com/bid/53477 https://exchange.xforce.ibmcloud.com/vulnerabilities/75521 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-2920 – User Photo <= 0.9.5 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-2920
Cross-site scripting (XSS) vulnerability in the userphoto_options_page function in user-photo.php in the User Photo plugin before 0.9.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to wp-admin/options-general.php. NOTE: some of these details are obtained from third party information. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la función userphoto_options_page de user-photo.php del complemento User Photo en versiones anteriores a la 0.9.5.2 de WordPress. Permite a atacantes remotos inyectar codigo de script web o código HTML de su elección a través de PATH_INFO de wp-admin/options-general.php. NOTA: algunos de estos detalles han sido obtenidos de información procedente de terceras partes. • http://osvdb.org/81806 http://plugins.trac.wordpress.org/changeset?old_path=%2Fuser-photo&old=541880&new_path=%2Fuser-photo&new=541880 http://secunia.com/advisories/49100 http://wordpress.org/extend/plugins/user-photo/changelog http://www.securityfocus.com/bid/53449 https://exchange.xforce.ibmcloud.com/vulnerabilities/75496 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-4283 – Login With Ajax < 3.0.4.1 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-4283
Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en el plugin 'Login With Ajax' antes de v3.0.4.1 para WordPress permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro de devolución de llamada (callback). • http://plugins.trac.wordpress.org/changeset/541069 http://secunia.com/advisories/49013 http://wordpress.org/extend/plugins/login-with-ajax/changelog • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •