VDB

DEBIAN-CVE-2013-2205

DEBIAN-CVE-2013-2205 PUBLISHED CVSS 9.300000190734863 CRITICAL

The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:12wordpress0, 0, 0
Debian:13wordpress0, 0, 0
Debian:14wordpress0
Debian:11wordpress0, 0, 0

Timeline

  • Jul 8, 2013 CVE Published
  • May 7, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›