MEDIUM · 4.3

CVE-2013-2204

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extractio...

Vulnerability Description

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
TinymceMedia-
WordpressWordpress<= 3.5.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-2204?

CVE-2013-2204 is a vulnerability with a CVSS score of 4.3 (MEDIUM). moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extractio...

How severe is CVE-2013-2204?

CVE-2013-2204 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-2204?

Check the references section above for vendor advisories and patch information. Affected products include: Tinymce Media, Wordpress Wordpress.