CVE-2012-6506 – Zingiri Web Shop Plugin <= 2.4.1 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-6506
Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in zing.inc.php or (2) notes parameter in fws/pages-front/onecheckout.php. Múltiples vulnerabilidades de tipo cross-site scripting (XSS) en el plugin Zingiri Web Shop versión 2.4.0 para WordPress, permiten a los atacantes remotos inyectar script web o HTML arbitrario por medio de los parámetros (1) page en el archivo zing.inc.php o (2) notes en el archivo fws/pages-front/onecheckout.php. Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in zing.inc.php or (2) notes parameter in fws/pages-front/onecheckout.php. • https://www.exploit-db.com/exploits/18787 http://plugins.trac.wordpress.org/changeset?reponame=&old=537613%40zingiri-web-shop&new=537613%40zingiri-web-shop http://secunia.com/advisories/48991 http://wordpress.org/extend/plugins/zingiri-web-shop/changelog http://www.exploit-db.com/exploits/18787 http://www.osvdb.org/81492 http://www.osvdb.org/81493 http://www.securityfocus.com/bid/53278 https://exchange.xforce.ibmcloud.com/vulnerabilities/75178 https://exchange.xforce.ibmcloud.com/v • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-4332 – ShareYourCart < 1.7.1 - Sensitive Information Disclosure
https://notcve.org/view.php?id=CVE-2012-4332
The ShareYourCart plugin 1.7.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors related to the SDK. El plug-in para WordPress ShareYourCart v1.7.1 permite a atacantes remotos obtener la ruta de instalación a través de vectores no especificados relacionados con el SDK. The ShareYourCart plugin before 1.7.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors related to the SDK. • http://secunia.com/advisories/48960 http://wordpress.org/extend/plugins/shareyourcart/changelog http://www.securityfocus.com/bid/53241 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2012-2399 – WordPress Core <= 3.5.1 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-2399
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414. Vulnerabilidad no especificada en wp-includes/js/swfupload/swfupload.swf en WordPress antes de v3.3.2 tiene un impacto y vectores de ataque desconocidos. • http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/swfupload/swfupload.swf?rev=20503 http://jvn.jp/en/jp/JVN25280162/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2012-002110 http://make.wordpress.org/core/2013/06/21/secure-swfupload http://osvdb.org/81459 http://packetstormsecurity.com/files/120746/SWFUpload-Content-Spoofing-Cross-Site-Scripting.html http://packetstormsecurity.com/files/122399/tinymce11-xss.txt http://seclists.org/fulldisclosure/2013/Mar/110 http:/ • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-2404 – WordPress Core <= 3.3.1 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-2404
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. wp-comments-post.php en WordPress antes de v3.3.2 soporta redirecciones afuera del sitio, lo que hace que facilita a los atacantes remotos a la hora de realizar ataques de ejecuciónde comandos en sitios cruzados (XSS) a través de vectores no especificados. • http://core.trac.wordpress.org/changeset/20486/branches/3.3/wp-comments-post.php http://osvdb.org/81464 http://secunia.com/advisories/48957 http://secunia.com/advisories/49138 http://wordpress.org/news/2012/04/wordpress-3-3-2 http://www.debian.org/security/2012/dsa-2470 http://www.securityfocus.com/bid/53192 https://exchange.xforce.ibmcloud.com/vulnerabilities/75092 https://exchange.xforce.ibmcloud.com/vulnerabilities/75202 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-2400 – WordPress Core < 3.3.2 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-2400
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors. Vulnerabilidad no especificada en wp-includes/js/swfobject.js en WordPress antes de v3.3.2 tiene un impacto y vectores de ataque desconocidos. • http://core.trac.wordpress.org/changeset/20499/branches/3.3/wp-includes/js/swfobject.js http://osvdb.org/81460 http://secunia.com/advisories/49138 http://wordpress.org/news/2012/04/wordpress-3-3-2 http://www.debian.org/security/2012/dsa-2470 http://www.securityfocus.com/bid/53192 https://exchange.xforce.ibmcloud.com/vulnerabilities/75209 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •