First published: Fri Jul 19 2013(Updated: )
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Swfupload Project Swfupload | <=2.2.0.1 | |
Swfupload Project Swfupload | =1.0.2 | |
Swfupload Project Swfupload | =2.0.2 | |
Swfupload Project Swfupload | =2.1.0 | |
Swfupload Project Swfupload | =2.2.0 | |
TinyMCE Image Manager | =1.1 | |
WordPress WordPress | <=3.3.1 | |
WordPress WordPress | ||
WordPress WordPress | =3.0 | |
WordPress WordPress | =3.0.1 | |
WordPress WordPress | =3.0.2 | |
WordPress WordPress | =3.0.3 | |
WordPress WordPress | =3.0.4 | |
WordPress WordPress | =3.0.5 | |
WordPress WordPress | =3.0.6 | |
WordPress WordPress | =3.1 | |
WordPress WordPress | =3.1.1 | |
WordPress WordPress | =3.1.2 | |
WordPress WordPress | =3.1.3 | |
WordPress WordPress | =3.1.4 | |
WordPress WordPress | =3.2 | |
WordPress WordPress | =3.2.1 | |
WordPress WordPress | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.