2.6
CVSSv2

CVE-2013-4954

Published: 29/07/2013 Updated: 29/08/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 265
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin prior to 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote malicious users to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in a register action. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

genetechsolutions pie-register 1.2.9

genetechsolutions pie-register 1.2.1

genetechsolutions pie-register 1.2.0

genetechsolutions pie-register 1.1.3

genetechsolutions pie-register 1.1.2

genetechsolutions pie-register 1.2.91

genetechsolutions pie-register 1.2.3

genetechsolutions pie-register 1.2.2

genetechsolutions pie-register 1.1.6

genetechsolutions pie-register 1.1.5

genetechsolutions pie-register 1.2.6

genetechsolutions pie-register 1.2.4

genetechsolutions pie-register 1.1.8

genetechsolutions pie-register 1.1.7

genetechsolutions pie-register 1.2.8

genetechsolutions pie-register 1.2.7

genetechsolutions pie-register 1.1.9

genetechsolutions pie-register 1.1.1

genetechsolutions pie-register 1.0.1

genetechsolutions pie-register

Exploits

source: wwwsecurityfocuscom/bid/61140/info Pie Register plugin for WordPress is prone to multiple cross-site scripting vulnerabilities An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may allow the attacker to steal cookie-based authen ...