CVE-2012-6634

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
wordpresswordpress
𝑥
≤ 3.3.2
wordpresswordpress
3.0
wordpresswordpress
3.0.1
wordpresswordpress
3.0.2
wordpresswordpress
3.0.3
wordpresswordpress
3.0.4
wordpresswordpress
3.0.5
wordpresswordpress
3.0.6
wordpresswordpress
3.1
wordpresswordpress
3.1.1
wordpresswordpress
3.1.2
wordpresswordpress
3.1.3
wordpresswordpress
3.1.4
wordpresswordpress
3.2
wordpresswordpress
3.2:beta1
wordpresswordpress
3.2.1
wordpresswordpress
3.3
wordpresswordpress
3.3.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wordpress
bullseye (security)
5.7.11+dfsg1-0+deb11u1
fixed
bullseye
5.7.11+dfsg1-0+deb11u1
fixed
bookworm
6.1.6+dfsg1-0+deb12u1
fixed
bookworm (security)
6.1.6+dfsg1-0+deb12u1
fixed
sid
6.6.1+dfsg1-1
fixed
trixie
6.6.1+dfsg1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wordpress
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
ignored
lucid
ignored
Common Weakness Enumeration