Lucene search

K
cve[email protected]CVE-2011-5182
HistorySep 20, 2012 - 10:55 a.m.

CVE-2011-5182

2012-09-2010:55:26
CWE-79
web.nvd.nist.gov
24
cve
2011
5182
cross-site scripting
xss
vulnerability
lanoba social plugin
wordpress

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.4%

Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor disputes this issue, stating "Lanoba’s plug in does sanitize user input, and because that input is never sent to the browser, an attacker has no way of executing script or code on a user’s behalf.

Affected configurations

NVD
Node
wordpresslanoba_social_pluginMatch1.0
AND
wordpresswordpressMatch-

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.4%

Related for CVE-2011-5182