Lucene search

K
freebsdFreeBSDA467D0F9-8875-11DC-B3BA-0016179B2DD5
HistoryOct 29, 2007 - 12:00 a.m.

wordpress -- cross-site scripting

2007-10-2900:00:00
vuxml.freebsd.org
13

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS

0.008

Percentile

81.7%

A Secunia Advisory report:

Input passed to the “posts_columns” parameter in
wp-admin/edit-post-rows.php is not properly sanitised before
being returned to the user. This can be exploited to execute
arbitrary HTML and script code in a user’s browser session in
context of an affected site.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchwordpress< 2.3.1UNKNOWN
FreeBSDanynoarchde-wordpress< 2.3.1UNKNOWN

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS

0.008

Percentile

81.7%