Lucene search

K
cveMitreCVE-2009-1030
HistoryMar 20, 2009 - 12:30 a.m.

CVE-2009-1030

2009-03-2000:30:00
CWE-79
mitre
web.nvd.nist.gov
46
cve-2009-1030
cross-site scripting
xss
vulnerability
wordpress mu
wpmu
web script
html
http host header

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.005

Percentile

77.1%

Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

Affected configurations

Nvd
Node
wordpresswordpress_muRange2.6
OR
wordpresswordpress_muMatch1.0
OR
wordpresswordpress_muMatch1.0rc1
OR
wordpresswordpress_muMatch1.0rc2
OR
wordpresswordpress_muMatch1.0rc3
OR
wordpresswordpress_muMatch1.0rc4
OR
wordpresswordpress_muMatch1.1
OR
wordpresswordpress_muMatch1.1.1
OR
wordpresswordpress_muMatch1.2
OR
wordpresswordpress_muMatch1.2.1
OR
wordpresswordpress_muMatch1.2.2
OR
wordpresswordpress_muMatch1.2.3
OR
wordpresswordpress_muMatch1.2.4
OR
wordpresswordpress_muMatch1.2.4rc1
OR
wordpresswordpress_muMatch1.2.5a
OR
wordpresswordpress_muMatch1.3
OR
wordpresswordpress_muMatch1.3.1
OR
wordpresswordpress_muMatch1.3.2
OR
wordpresswordpress_muMatch1.3.3
OR
wordpresswordpress_muMatch1.5rc1
OR
wordpresswordpress_muMatch1.5.1
OR
wordpresswordpress_muMatch2.6.1
OR
wordpresswordpress_muMatch2.6.2
OR
wordpresswordpress_muMatch2.6.3
OR
wordpresswordpress_muMatch2.6.5
OR
wordpresswordpress_muMatch2.7
VendorProductVersionCPE
wordpresswordpress_mu1.0cpe:/a:wordpress:wordpress_mu:1.0:rc2::
wordpresswordpress_mu1.2cpe:/a:wordpress:wordpress_mu:1.2:::
wordpresswordpress_mu2.6.2cpe:/a:wordpress:wordpress_mu:2.6.2:::
wordpresswordpress_mu1.3.3cpe:/a:wordpress:wordpress_mu:1.3.3:::
wordpresswordpress_mu1.3.1cpe:/a:wordpress:wordpress_mu:1.3.1:::
wordpresswordpress_mucpe:/a:wordpress:wordpress_mu::::
wordpresswordpress_mu1.2.3cpe:/a:wordpress:wordpress_mu:1.2.3:::
wordpresswordpress_mu1.2.4cpe:/a:wordpress:wordpress_mu:1.2.4:::
wordpresswordpress_mu1.1cpe:/a:wordpress:wordpress_mu:1.1:::
wordpresswordpress_mu1.1.1cpe:/a:wordpress:wordpress_mu:1.1.1:::
Rows per page:
1-10 of 261

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.005

Percentile

77.1%