Bad Behavior < 2.0.47 & 2.2.0 - 2.2.4 - Cross-Site Scripting

2012-05-11 00:00
SiNA Rabbani

Strategic Overview

Status
Patched in 2.0.47
Affected PluginBad Behavior
Affected Version2.0.47 – < 2.2.5 · 2 branches
CVSS6.1Medium
CVECVE-2012-4271
View all Bad Behavior vulnerabilities

Vulnerability Overview

Multiple cross-site scripting (XSS) vulnerabilities in bad-behavior-wordpress-admin.php in the Bad Behavior plugin before 2.0.47 and 2.2.x before 2.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) httpbl_key, (3) httpbl_maxage, (4) httpbl_threat, (5) reverse_proxy_addresses, or (6) reverse_proxy_header parameter.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 2.0.47, 2.2.5 --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C