4.3
CVE-2012-4263
- EPSS 0.28%
- Veröffentlicht 13.08.2012 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
iThemes Security < 3.2.5 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.
Mögliche Gegenmaßnahme
Solid Security – Password, Two Factor Authentication, and Brute Force Protection: Update to version 3.2.5, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Solid Security – Password, Two Factor Authentication, and Brute Force Protection
Version
[*, 3.2.5)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bit51 ≫ Better-wp-security Version <= 3.2.4
Bit51 ≫ Better-wp-security Version- Updatealpha1
Bit51 ≫ Better-wp-security Version- Updatealpha10
Bit51 ≫ Better-wp-security Version- Updatealpha11
Bit51 ≫ Better-wp-security Version- Updatealpha2
Bit51 ≫ Better-wp-security Version- Updatealpha3
Bit51 ≫ Better-wp-security Version- Updatealpha4
Bit51 ≫ Better-wp-security Version- Updatealpha5
Bit51 ≫ Better-wp-security Version- Updatealpha6
Bit51 ≫ Better-wp-security Version- Updatealpha7
Bit51 ≫ Better-wp-security Version- Updatealpha8
Bit51 ≫ Better-wp-security Version- Updatealpha9
Bit51 ≫ Better-wp-security Version0.1 Updatealpha
Bit51 ≫ Better-wp-security Version0.1 Updatebeta
Bit51 ≫ Better-wp-security Version0.2 Updatebeta
Bit51 ≫ Better-wp-security Version0.3 Updatebeta
Bit51 ≫ Better-wp-security Version0.4 Updatebeta
Bit51 ≫ Better-wp-security Version0.5 Updatebeta
Bit51 ≫ Better-wp-security Version0.6 Updatebeta
Bit51 ≫ Better-wp-security Version0.7 Updatebeta
Bit51 ≫ Better-wp-security Version0.8 Updatebeta
Bit51 ≫ Better-wp-security Version0.9 Updatebeta
Bit51 ≫ Better-wp-security Version0.10 Updatebeta
Bit51 ≫ Better-wp-security Version0.11 Updatebeta
Bit51 ≫ Better-wp-security Version0.13 Updatebeta
Bit51 ≫ Better-wp-security Version0.14 Updatebeta
Bit51 ≫ Better-wp-security Version0.15 Updatebeta
Bit51 ≫ Better-wp-security Version0.16 Updatebeta
Bit51 ≫ Better-wp-security Version1.0
Bit51 ≫ Better-wp-security Version1.1
Bit51 ≫ Better-wp-security Version1.2
Bit51 ≫ Better-wp-security Version1.3
Bit51 ≫ Better-wp-security Version1.4
Bit51 ≫ Better-wp-security Version1.5
Bit51 ≫ Better-wp-security Version1.6
Bit51 ≫ Better-wp-security Version1.7
Bit51 ≫ Better-wp-security Version1.8
Bit51 ≫ Better-wp-security Version1.8.1
Bit51 ≫ Better-wp-security Version1.9
Bit51 ≫ Better-wp-security Version2.0
Bit51 ≫ Better-wp-security Version2.1
Bit51 ≫ Better-wp-security Version2.2
Bit51 ≫ Better-wp-security Version2.3
Bit51 ≫ Better-wp-security Version2.4
Bit51 ≫ Better-wp-security Version2.5
Bit51 ≫ Better-wp-security Version2.6
Bit51 ≫ Better-wp-security Version2.7
Bit51 ≫ Better-wp-security Version2.8
Bit51 ≫ Better-wp-security Version2.9
Bit51 ≫ Better-wp-security Version2.10
Bit51 ≫ Better-wp-security Version2.11
Bit51 ≫ Better-wp-security Version2.12
Bit51 ≫ Better-wp-security Version2.13
Bit51 ≫ Better-wp-security Version2.14
Bit51 ≫ Better-wp-security Version2.15
Bit51 ≫ Better-wp-security Version2.16
Bit51 ≫ Better-wp-security Version2.17
Bit51 ≫ Better-wp-security Version2.18
Bit51 ≫ Better-wp-security Version3.0
Bit51 ≫ Better-wp-security Version3.0.1
Bit51 ≫ Better-wp-security Version3.0.2
Bit51 ≫ Better-wp-security Version3.0.3
Bit51 ≫ Better-wp-security Version3.0.4
Bit51 ≫ Better-wp-security Version3.0.5
Bit51 ≫ Better-wp-security Version3.0.6
Bit51 ≫ Better-wp-security Version3.0.7
Bit51 ≫ Better-wp-security Version3.0.8
Bit51 ≫ Better-wp-security Version3.0.9
Bit51 ≫ Better-wp-security Version3.0.10
Bit51 ≫ Better-wp-security Version3.0.11
Bit51 ≫ Better-wp-security Version3.0.12
Bit51 ≫ Better-wp-security Version3.1
Bit51 ≫ Better-wp-security Version3.2
Bit51 ≫ Better-wp-security Version3.2.1
Bit51 ≫ Better-wp-security Version3.2.2
Bit51 ≫ Better-wp-security Version3.2.3
Bit51 ≫ Better-wp-security Version3.2.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.51 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.