VDB
DEBIAN-CVE-2013-2205
DEBIAN-CVE-2013-2205
PUBLISHED
CVSS 9.300000190734863 CRITICAL
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | wordpress | 0, 0, 0 |
| Debian:13 | wordpress | 0, 0, 0 |
| Debian:14 | wordpress | 0 |
| Debian:11 | wordpress | 0, 0, 0 |
Timeline
- Jul 8, 2013 CVE Published
- May 7, 2026 CVE Updated