CVE-2012-3414
Swfupload < 2.2.0.1 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Nathan Partlan · textwebappsmultiple
https://www.exploit-db.com/exploits/37470
References (8)
Scores
EPSS
0.0626
EPSS Percentile
90.8%
Details
CWE
CWE-79
Status
published
Products (24)
swfupload_project/swfupload
< 2.2.0.1
swfupload_project/swfupload
swfupload_project/swfupload
swfupload_project/swfupload
swfupload_project/swfupload
tinymce/image_manager
wordpress/wordpress
< 3.3.1
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
... and 14 more
Published
Jul 19, 2013
Tracked Since
Feb 18, 2026