| Vulnerability Name: | CVE-2012-5349 (CCN-72166) | ||||||||
| Assigned: | 2012-01-06 | ||||||||
| Published: | 2012-01-06 | ||||||||
| Updated: | 2017-08-29 | ||||||||
| Summary: | Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) title, or (3) dl parameter. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 2.4 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
| ||||||||
| Vulnerability Type: | CWE-79 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2012-5349 Source: CCN Type: SA47475 WordPress Pay With Tweet Plugin Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 47475 Source: CCN Type: Pay With Tweet plugin for WordPress Web Site WordPress Pay With Tweet « WordPress Plugins Source: CONFIRM Type: UNKNOWN http://wordpress.org/extend/plugins/pay-with-tweet/changelog/ Source: EXPLOIT-DB Type: Exploit 18330 Source: OSVDB Type: UNKNOWN 78205 Source: CCN Type: OSVDB ID: 78205 Pay With Tweet Plugin for WordPress wp-content/plugins/pay-with-tweet.php/pay.php Multiple Parameter XSS Source: BID Type: Exploit 51308 Source: CCN Type: BID-51308 WordPress Pay With Tweet Plugin SQL Injection and Cross Site Scripting Vulnerabilities Source: XF Type: UNKNOWN paywithtweet-pay-xss(72166) Source: XF Type: UNKNOWN paywithtweet-pay-xss(72166) Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [01-06-2012] | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||