VYPR

TinyMCE Media

by WordPress

CVEs (1)

  • CVE-2013-2204Jul 8, 2013
    risk 0.00cvss epss 0.03

    moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary…