4.3

CVE-2007-1894

WordPress Core <= 2.1.2 - Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.
Mögliche Gegenmaßnahme
WordPress: Update to one of the following versions, or a newer patched version: 2.0.10, 2.1.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wordpress ≫ Wordpress Version 2.0
Wordpress ≫ Wordpress Version 2.0.1
Wordpress ≫ Wordpress Version 2.0.2
Wordpress ≫ Wordpress Version 2.0.3
Wordpress ≫ Wordpress Version 2.0.4
Wordpress ≫ Wordpress Version 2.0.5
Wordpress ≫ Wordpress Version 2.0.6
Wordpress ≫ Wordpress Version 2.0.7
Wordpress ≫ Wordpress Version 2.1
Wordpress ≫ Wordpress Version 2.1.1
Wordpress ≫ Wordpress Version 2.1.2
Wordpress ≫ Wordpress Version 2.2_revision5002
Weitere Schwachstelleninformationen
SystemWordPress Core
≫
Produkt WordPress
Version *-2.0.9
Version 2.1-2.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.02% 0.857
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/25108
http://www.debian.org/security/2007/dsa-1285
http://chxsecurity.org/advisories/adv-1-mid.txt
Vendor Advisory
http://secunia.com/advisories/24485
Patch
Vendor Advisory
http://securityreason.com/securityalert/2526
http://trac.wordpress.org/changeset/5003
http://trac.wordpress.org/ticket/4093
http://www.securityfocus.com/archive/1/462374/100/0/threaded
http://www.securityfocus.com/bid/22902
Patch
https://www.wordfence.com/threat-intel/vulnerabilities/id/c7d04f7d-d114-4104-a7cb-298c148e2b6d
Third Party Advisory