Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2013-4144
Disclosure Date: June 30, 2022 (last updated October 07, 2023)
There is an object injection vulnerability in swfupload plugin for wordpress.
0
Attacker Value
Unknown
CVE-2012-3414
Disclosure Date: July 19, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
0