5
CVE-2012-6112
- EPSS 2.29%
- Veröffentlicht 27.01.2013 22:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tinymce ≫ Spellchecker Php Version 2.0
Tinymce ≫ Spellchecker Php Version 2.0 Update a1
Tinymce ≫ Spellchecker Php Version 2.0 Update a2
Tinymce ≫ Spellchecker Php Version 2.0 Update b1
Tinymce ≫ Spellchecker Php Version 2.0 Update b2
Tinymce ≫ Spellchecker Php Version 2.0 Update b3
Tinymce ≫ Spellchecker Php Version 2.0 Update rc1
Tinymce ≫ Spellchecker Php Version 2.0.1
Tinymce ≫ Spellchecker Php Version 2.0.2
Tinymce ≫ Spellchecker Php Version 2.0.3
Tinymce ≫ Spellchecker Php Version 2.0.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.29% | 0.809 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://openwall.com/lists/oss-security/2013/01/21/1
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37283
http://www.tinymce.com/develop/changelog/?type=phpspell
http://www.tinymce.com/forum/viewtopic.php?id=30036
https://github.com/tinymce/tinymce_spellchecker_php/commit/22910187bfb9edae90c26e10100d8145b505b974
https://moodle.org/mod/forum/discuss.php?d=220157