FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-2204

This CVE name corresponds to:

Entered Topic
2013-07-27 wordpress -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-2204
Phase Assigned(20130219)

Description

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

References

Source Reference
CONFIRM http://codex.wordpress.org/Version_3.5.2
CONFIRM http://wordpress.org/news/2013/06/wordpress-3-5-2/
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=976784
CONFIRM https://github.com/moxiecode/moxieplayer/commit/b61ac518ffa2657e2dc9019b2dcf2f3f37dbfab0
DEBIAN DSA-2718