Published: 02-12-2009
Updated: 10-03-2010
Product:
roytanck: wp-cumulus 1.00
roytanck: wp-cumulus 1.01
roytanck: wp-cumulus 1.02
roytanck: wp-cumulus 1.03
roytanck: wp-cumulus 1.04
roytanck: wp-cumulus 1.05
roytanck: wp-cumulus 1.10
roytanck: wp-cumulus 1.11
roytanck: wp-cumulus 1.12
roytanck: wp-cumulus 1.13
roytanck: wp-cumulus 1.14
roytanck: wp-cumulus 1.15
roytanck: wp-cumulus 1.16
roytanck: wp-cumulus 1.17
roytanck: wp-cumulus 1.18
roytanck: wp-cumulus 1.19
roytanck: wp-cumulus 1.2.1
roytanck: wp-cumulus 1.20
roytanck: wp-cumulus 1.22
Severity: Medium (4.3)
CVSS vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Attack`s vector: Victim must voluntarily interact with attack mechanism
Potential loss type: Integrity
Vulnerability description:
Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS) vulnerability in tagcloud.swf in the WP-Cumulus Plug-in before 1.23 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter.
Patch available: No
References:
XF: http://xforce.iss.net/xforce/xfdb/55156
XF: http://xforce.iss.net/xforce/xfdb/54397
VUPEN: http://www.vupen.com/english/advisories/2009/3322
BID: http://www.securityfocus.com/bid/37479
BID: http://www.securityfocus.com/bid/37100
BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/508833/100/0/threaded ...
BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/508606/100/0/threaded ...
BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/508071/100/0/threaded ...
CONFIRM: http://www.roytanck.com/2009/11/15/wp-cumulus-updated-to-address-yet-a ...
MISC: http://websecurity.com.ua/3839/
MISC: http://websecurity.com.ua/3801/
MISC: http://websecurity.com.ua/3789/
MISC: http://websecurity.com.ua/3665/
SECUNIA: http://secunia.com/advisories/38161
SECUNIA: http://secunia.com/advisories/37483
MISC: http://packetstormsecurity.org/1001-exploits/joomlajvclouds-xss.txt
