CVE-2012-0782

Source
https://cve.org/CVERecord?id=CVE-2012-0782
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2012-0782.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2012-0782
Downstream
Published
2012-01-30T17:55:00Z
Modified
2026-04-10T03:42:11.826654Z
Summary
[none]
Details

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether this specific XSS scenario has security relevance

Database specific
{
    "isDisputed": true
}
References

Affected packages