4.3

CVE-2012-4264

Exploit

Better WP Security <= 3.2.4 - Multiple Cross-Site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263.
Mögliche Gegenmaßnahme
Solid Security – Password, Two Factor Authentication, and Brute Force Protection: Update to version 3.2.5, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Solid Security – Password, Two Factor Authentication, and Brute Force Protection
Version *-3.2.4
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bit51Better-wp-security Version <= 3.2.4
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha1
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha10
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha11
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha2
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha3
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha4
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha5
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha6
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha7
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha8
   WordpressWordpress Version-
Bit51Better-wp-security Version- Updatealpha9
   WordpressWordpress Version-
Bit51Better-wp-security Version0.1 Updatealpha
   WordpressWordpress Version-
Bit51Better-wp-security Version0.1 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.2 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.3 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.4 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.5 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.6 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.7 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.8 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.9 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.10 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.11 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.13 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.14 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.15 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version0.16 Updatebeta
   WordpressWordpress Version-
Bit51Better-wp-security Version1.0
   WordpressWordpress Version-
Bit51Better-wp-security Version1.1
   WordpressWordpress Version-
Bit51Better-wp-security Version1.2
   WordpressWordpress Version-
Bit51Better-wp-security Version1.3
   WordpressWordpress Version-
Bit51Better-wp-security Version1.4
   WordpressWordpress Version-
Bit51Better-wp-security Version1.5
   WordpressWordpress Version-
Bit51Better-wp-security Version1.6
   WordpressWordpress Version-
Bit51Better-wp-security Version1.7
   WordpressWordpress Version-
Bit51Better-wp-security Version1.8
   WordpressWordpress Version-
Bit51Better-wp-security Version1.8.1
   WordpressWordpress Version-
Bit51Better-wp-security Version1.9
   WordpressWordpress Version-
Bit51Better-wp-security Version2.0
   WordpressWordpress Version-
Bit51Better-wp-security Version2.1
   WordpressWordpress Version-
Bit51Better-wp-security Version2.2
   WordpressWordpress Version-
Bit51Better-wp-security Version2.3
   WordpressWordpress Version-
Bit51Better-wp-security Version2.4
   WordpressWordpress Version-
Bit51Better-wp-security Version2.5
   WordpressWordpress Version-
Bit51Better-wp-security Version2.6
   WordpressWordpress Version-
Bit51Better-wp-security Version2.7
   WordpressWordpress Version-
Bit51Better-wp-security Version2.8
   WordpressWordpress Version-
Bit51Better-wp-security Version2.9
   WordpressWordpress Version-
Bit51Better-wp-security Version2.10
   WordpressWordpress Version-
Bit51Better-wp-security Version2.11
   WordpressWordpress Version-
Bit51Better-wp-security Version2.12
   WordpressWordpress Version-
Bit51Better-wp-security Version2.13
   WordpressWordpress Version-
Bit51Better-wp-security Version2.14
   WordpressWordpress Version-
Bit51Better-wp-security Version2.15
   WordpressWordpress Version-
Bit51Better-wp-security Version2.16
   WordpressWordpress Version-
Bit51Better-wp-security Version2.17
   WordpressWordpress Version-
Bit51Better-wp-security Version2.18
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.1
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.2
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.3
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.4
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.5
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.6
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.7
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.8
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.9
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.10
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.11
   WordpressWordpress Version-
Bit51Better-wp-security Version3.0.12
   WordpressWordpress Version-
Bit51Better-wp-security Version3.1
   WordpressWordpress Version-
Bit51Better-wp-security Version3.2
   WordpressWordpress Version-
Bit51Better-wp-security Version3.2.1
   WordpressWordpress Version-
Bit51Better-wp-security Version3.2.2
   WordpressWordpress Version-
Bit51Better-wp-security Version3.2.3
   WordpressWordpress Version-
Bit51Better-wp-security Version3.2.5
   WordpressWordpress Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.469
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.