CVE-2012-6112
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.
classes/GoogleSpell.php en PHP Spellchecker (también conocido como Google Spellchecker) complemento anterior a v2.0.6.1 para TinyMCE, también usado en Moodle v2.1.x anterior a v2.1.10, v2.2.x anterior a v2.2.7, v2.3.x anterior a v2.3.4, y 2.4.x anterior a v2.4.1 y otros productos, no maneja adecuadamente los caracteres de control, lo que permite a atacantes remotos ejecutar peticiones arbitrarias HTTP fuera de límite, a través de cadenas modificadas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-12-06 CVE Reserved
- 2013-01-27 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37283 | X_refsource_confirm | |
http://openwall.com/lists/oss-security/2013/01/21/1 | Mailing List | |
http://www.tinymce.com/develop/changelog/?type=phpspell | X_refsource_confirm | |
https://github.com/tinymce/tinymce_spellchecker_php/commit/22910187bfb9edae90c26e10100d8145b505b974 | X_refsource_confirm | |
https://moodle.org/mod/forum/discuss.php?d=220157 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.tinymce.com/forum/viewtopic.php?id=30036 | 2020-12-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0" | - |
Affected
| ||||||
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0" | a1 |
Affected
| ||||||
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0" | a2 |
Affected
| ||||||
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0" | b1 |
Affected
| ||||||
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0" | b2 |
Affected
| ||||||
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0" | b3 |
Affected
| ||||||
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0" | rc1 |
Affected
| ||||||
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0.1 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0.1" | - |
Affected
| ||||||
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0.2 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0.2" | - |
Affected
| ||||||
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0.3 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0.3" | - |
Affected
| ||||||
Tinymce Search vendor "Tinymce" | Spellchecker Php Search vendor "Tinymce" for product "Spellchecker Php" | 2.0.6 Search vendor "Tinymce" for product "Spellchecker Php" and version "2.0.6" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.0 Search vendor "Moodle" for product "Moodle" and version "2.1.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.1 Search vendor "Moodle" for product "Moodle" and version "2.1.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.2 Search vendor "Moodle" for product "Moodle" and version "2.1.2" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.3 Search vendor "Moodle" for product "Moodle" and version "2.1.3" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.4 Search vendor "Moodle" for product "Moodle" and version "2.1.4" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.5 Search vendor "Moodle" for product "Moodle" and version "2.1.5" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.6 Search vendor "Moodle" for product "Moodle" and version "2.1.6" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.7 Search vendor "Moodle" for product "Moodle" and version "2.1.7" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.8 Search vendor "Moodle" for product "Moodle" and version "2.1.8" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.9 Search vendor "Moodle" for product "Moodle" and version "2.1.9" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.0 Search vendor "Moodle" for product "Moodle" and version "2.2.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.1 Search vendor "Moodle" for product "Moodle" and version "2.2.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.2 Search vendor "Moodle" for product "Moodle" and version "2.2.2" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.3 Search vendor "Moodle" for product "Moodle" and version "2.2.3" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.4 Search vendor "Moodle" for product "Moodle" and version "2.2.4" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.5 Search vendor "Moodle" for product "Moodle" and version "2.2.5" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.2.6 Search vendor "Moodle" for product "Moodle" and version "2.2.6" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.3.0 Search vendor "Moodle" for product "Moodle" and version "2.3.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.3.1 Search vendor "Moodle" for product "Moodle" and version "2.3.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.3.2 Search vendor "Moodle" for product "Moodle" and version "2.3.2" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.3.3 Search vendor "Moodle" for product "Moodle" and version "2.3.3" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.4.0 Search vendor "Moodle" for product "Moodle" and version "2.4.0" | - |
Affected
|