6.8
CVSSv2

CVE-2006-1796

Published: 17/04/2006 Updated: 05/09/2008
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions prior to 2.0.1, allows remote malicious users to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']).

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress 1.0.1

wordpress wordpress 1.2

wordpress wordpress 1.5.1.2

wordpress wordpress 1.5.2

wordpress wordpress

wordpress wordpress 0.6.2.1

wordpress wordpress 0.6.2

wordpress wordpress 0.7

wordpress wordpress 0.71

wordpress wordpress 1.2.1

wordpress wordpress 1.2.2

wordpress wordpress 1.5

wordpress wordpress 1.5.1

wordpress wordpress 1.0

wordpress wordpress 1.0.2

wordpress wordpress 1.5.1.3

wordpress wordpress 2.0

Vendor Advisories

Debian Bug report logs - #328909 wordpress: CSS Security Vulnerability Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Noam Rathaus <noamr@beyondsecuritycom> Date: Sun, 18 Sep 2005 06:48:02 UTC Severity: minor ...