Vulnerability Name:

CVE-2013-2205 (CCN-85364)

Assigned:2013-06-22
Published:2013-06-22
Updated:2016-12-31
Summary:The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
CVSS v3 Severity:2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
3.5 Low (CCN CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
CWE-16
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Wordpress Website
WordPress 3.5.2

Source: CONFIRM
Type: UNKNOWN
http://codex.wordpress.org/Version_3.5.2

Source: MITRE
Type: CNA
CVE-2013-2205

Source: CONFIRM
Type: UNKNOWN
http://make.wordpress.org/core/2013/06/21/secure-swfupload/

Source: CCN
Type: Seclists.org
Full Disclosure: [ MDVSA-2013:189 ] wordpress

Source: CCN
Type: SA53676
WordPress Password Protected Posts Denial of Service Vulnerability

Source: CONFIRM
Type: Vendor Advisory
http://wordpress.org/news/2013/06/wordpress-3-5-2/

Source: DEBIAN
Type: UNKNOWN
DSA-2718

Source: DEBIAN
Type: DSA-2718
wordpress -- several vulnerabilities

Source: BID
Type: UNKNOWN
60759

Source: CCN
Type: BID-60759
WordPress 'SWFUpload' Library CVE-2013-2205 Multiple Cross Site Scripting Vulnerabilities

Source: CCN
Type: Red Hat Bugzilla Bug 976784
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=976784

Source: XF
Type: UNKNOWN
wordpress-cve20132205-xss(85364)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:wordpress:wordpress:0.71:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.0:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.5:a:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.5:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.6:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.7:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.8:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.9:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.10:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.11:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.3:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.3:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.3.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.3.2:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.5:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.6:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.6.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.7:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.8:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.8.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.8.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.8.4:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.8.4:a:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.8.5:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.8.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.8.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.8.6:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.9:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.9.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.9.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.9.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:3.3:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:3.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:3.3.2:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:3.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:3.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:3.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:3.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:3.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:*:*:*:*:*:*:*:* (Version <= 3.5.1)

  • Configuration CCN 1:
  • cpe:/a:wordpress:wordpress:3.5:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:3.5.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:19614
    P
    DSA-2718-1 wordpress - several
    2014-06-23
    oval:com.ubuntu.precise:def:20132205000
    V
    CVE-2013-2205 on Ubuntu 12.04 LTS (precise) - medium.
    2013-07-08
    oval:com.ubuntu.xenial:def:201322050000000
    V
    CVE-2013-2205 on Ubuntu 16.04 LTS (xenial) - medium.
    2013-07-08
    oval:com.ubuntu.trusty:def:20132205000
    V
    CVE-2013-2205 on Ubuntu 14.04 LTS (trusty) - medium.
    2013-07-08
    oval:com.ubuntu.xenial:def:20132205000
    V
    CVE-2013-2205 on Ubuntu 16.04 LTS (xenial) - medium.
    2013-07-08
    BACK
    wordpress wordpress 0.71
    wordpress wordpress 1.0
    wordpress wordpress 1.0.1
    wordpress wordpress 1.0.2
    wordpress wordpress 1.1.1
    wordpress wordpress 1.2
    wordpress wordpress 1.2.1
    wordpress wordpress 1.2.2
    wordpress wordpress 1.2.3
    wordpress wordpress 1.2.4
    wordpress wordpress 1.2.5
    wordpress wordpress 1.2.5 a
    wordpress wordpress 1.3
    wordpress wordpress 1.3.2
    wordpress wordpress 1.3.3
    wordpress wordpress 1.5
    wordpress wordpress 1.5.1
    wordpress wordpress 1.5.1.1
    wordpress wordpress 1.5.1.2
    wordpress wordpress 1.5.1.3
    wordpress wordpress 1.5.2
    wordpress wordpress 1.6.2
    wordpress wordpress 2.0
    wordpress wordpress 2.0.1
    wordpress wordpress 2.0.2
    wordpress wordpress 2.0.4
    wordpress wordpress 2.0.5
    wordpress wordpress 2.0.6
    wordpress wordpress 2.0.7
    wordpress wordpress 2.0.8
    wordpress wordpress 2.0.9
    wordpress wordpress 2.0.10
    wordpress wordpress 2.0.11
    wordpress wordpress 2.1
    wordpress wordpress 2.1.1
    wordpress wordpress 2.1.2
    wordpress wordpress 2.1.3
    wordpress wordpress 2.2
    wordpress wordpress 2.2.1
    wordpress wordpress 2.2.2
    wordpress wordpress 2.2.3
    wordpress wordpress 2.3
    wordpress wordpress 2.3.1
    wordpress wordpress 2.3.2
    wordpress wordpress 2.3.3
    wordpress wordpress 2.5
    wordpress wordpress 2.5.1
    wordpress wordpress 2.6
    wordpress wordpress 2.6.1
    wordpress wordpress 2.6.2
    wordpress wordpress 2.6.3
    wordpress wordpress 2.6.5
    wordpress wordpress 2.7
    wordpress wordpress 2.7.1
    wordpress wordpress 2.8
    wordpress wordpress 2.8.1
    wordpress wordpress 2.8.2
    wordpress wordpress 2.8.3
    wordpress wordpress 2.8.4
    wordpress wordpress 2.8.4 a
    wordpress wordpress 2.8.5
    wordpress wordpress 2.8.5.1
    wordpress wordpress 2.8.5.2
    wordpress wordpress 2.8.6
    wordpress wordpress 2.9
    wordpress wordpress 2.9.1
    wordpress wordpress 2.9.1.1
    wordpress wordpress 2.9.2
    wordpress wordpress 3.3
    wordpress wordpress 3.3.1
    wordpress wordpress 3.3.2
    wordpress wordpress 3.3.3
    wordpress wordpress 3.4.0
    wordpress wordpress 3.4.1
    wordpress wordpress 3.4.2
    wordpress wordpress 3.5.0
    wordpress wordpress *
    wordpress wordpress 3.5
    wordpress wordpress 3.5.1