5

CVE-2007-4166

Unnamed < 1.2.17.1 and Unnamed SE < 1.0.3 - Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in index.php in the Unnamed theme 1.217, and Special Edition (SE) 1.02, before 20070804 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757, CVE-2007-4014, and CVE-2007-4165.  NOTE: some of these details are obtained from third party information.
Mögliche Gegenmaßnahme
Unnamed: Update to version 1.2.17.1, or a newer patched version
Unnamed SE: Update to version 1.0.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wordpress ≫ Unamed Theme Version 1.217
Wordpress ≫ Unamed Theme Se Version 1.02
Weitere Schwachstelleninformationen
SystemWordPress Theme
≫
Produkt Unnamed
Version *-1.2.17
SystemWordPress Theme
≫
Produkt Unnamed SE
Version *-1.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.08% 0.79
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/25215
http://osvdb.org/36604
http://secunia.com/advisories/26321
Vendor Advisory
http://xuyiyang.com/2007/06/29/unnamed-1-217/
https://exchange.xforce.ibmcloud.com/vulnerabilities/35821
https://www.wordfence.com/threat-intel/vulnerabilities/id/360cb170-a888-4b7f-8ea2-1d74a404f1df
Third Party Advisory