Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qm3h-34vf-g6fh

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

EPSS

Процентиль: 68%
0.00593
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 12 лет назад

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

nvd
почти 12 лет назад

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

debian
почти 12 лет назад

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media ...

EPSS

Процентиль: 68%
0.00593
Низкий

Дефекты

CWE-20