4.3
CVSSv2

CVE-2007-1049

Published: 21/02/2007 Updated: 08/03/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 prior to 2.0.9 and 2.1 prior to 2.1.1 allows remote malicious users to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress 1.5

wordpress wordpress 1.5.1

wordpress wordpress 2.0.3

wordpress wordpress 2.0.4

wordpress wordpress 2.0.5

wordpress wordpress 0.6.2

wordpress wordpress 0.7

wordpress wordpress 1.5.2

wordpress wordpress 2.0

wordpress wordpress 0.6.2.1

wordpress wordpress 1.5.1.2

wordpress wordpress 1.5.1.3

wordpress wordpress 2.0.6

wordpress wordpress 2.0.7

wordpress wordpress 0.71

wordpress wordpress 1.2.2

wordpress wordpress 2.0.1

wordpress wordpress 2.0.2

wordpress wordpress 1.2

wordpress wordpress 1.2.1

Exploits

source: wwwsecurityfocuscom/bid/22534/info WordPress is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user This may help the attacker steal cookie-based authentica ...