Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9263

Опубликовано: 12 окт. 2017
Источник: nvd
CVSS3: 4.7
CVSS2: 2.6
EPSS Низкий

Описание

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
Версия до 4.8.2 (включая)

EPSS

Процентиль: 76%
0.01002
Низкий

4.7 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.7
ubuntu
почти 8 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
debian
почти 8 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandb ...

CVSS3: 4.7
github
около 3 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

EPSS

Процентиль: 76%
0.01002
Низкий

4.7 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-20