CVE-2012-4271
Description
Multiple cross-site scripting (XSS) vulnerabilities in bad-behavior-wordpress-admin.php in the Bad Behavior plugin before 2.0.47 and 2.2.x before 2.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) httpbl_key, (3) httpbl_maxage, (4) httpbl_threat, (5) reverse_proxy_addresses, or (6) reverse_proxy_header parameter.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| mark_jaquith | bad_behavior | {"endIncluding":"2.0.46"} | |
| mark_jaquith | bad_behavior | 2.2.0 | |
| mark_jaquith | bad_behavior | 2.2.1 | |
| mark_jaquith | bad_behavior | 2.2.2 | |
| mark_jaquith | bad_behavior | 2.2.3 | |
| mark_jaquith | bad_behavior | 2.2.4 | |
| wordpress | wordpress | - | |
References
- http://packetstormsecurity.org/files/112619/WordPress-Bad-Behavior-Cross-Site-Scripting.html
- http://plugins.trac.wordpress.org/changeset?old_path=%2Fbad-behavior&old=543807&new_path=%2Fbad-behavior&new=543807
- http://www.securityfocus.com/bid/53477
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75521
- http://packetstormsecurity.org/files/112619/WordPress-Bad-Behavior-Cross-Site-Scripting.html
- http://plugins.trac.wordpress.org/changeset?old_path=%2Fbad-behavior&old=543807&new_path=%2Fbad-behavior&new=543807
- http://www.securityfocus.com/bid/53477
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75521
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.