CVE-2013-2204 Information
Feb 14, 2021
cve
Description
moxieplayer.as in Moxiecode moxieplayer as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products does not consider the presence of a (pound sign) character during extraction of the QUERY_STRING which allows remote attackers to pass arbitrary parameters to a Flash application and conduct content-spoofing attacks via a crafted string after a ? (question mark) character.
Reference
http://codex.wordpress.org/Version_3.5.2 http://wordpress.org/news/2013/06/wordpress-3-5-2/ http://www.debian.org/security/2013/dsa-2718 https://bugzilla.redhat.com/show_bug.cgi?id=976784 https://github.com/moxiecode/moxieplayer/commit/b61ac518ffa2657e2dc9019b2dcf2f3f37dbfab0
Share on: