Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-6112

Опубликовано: 27 янв. 2013
Источник: debian
EPSS Низкий

Описание

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tinymcenot-affectedpackage
wordpressfixed3.5.1+dfsg-2package
moodlefixed2.5-1package
wordpressfixed3.5.2+dfsg-1~deb6u1squeezepackage
moodlenot-affectedsqueezepackage
wordpressfixed3.5.2+dfsg-1~deb7u1wheezypackage
moodlefixed2.2.3.dfsg-2.6~wheezy2wheezypackage

Примечания

  • http://www.tinymce.com/develop/changelog/?type=phpspell

  • patch: https://github.com/tinymce/tinymce_spellchecker_php/commit/22910187bfb9edae90c26e10100d8145b505b974

  • http://www.tinymce.com/forum/viewtopic.php?id=30036

EPSS

Процентиль: 68%
0.006
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.

nvd
больше 12 лет назад

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.

github
около 3 лет назад

PHP Spellchecker addon for TinyMCE allows attackers to trigger arbitrary outbound HTTP requests

EPSS

Процентиль: 68%
0.006
Низкий