4.3

CVE-2008-5278

Exploit

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

Data is provided by the National Vulnerability Database (NVD)
WordpressWordpress Version <= 2.6.3
WordpressWordpress Version0.6.2
WordpressWordpress Version0.6.2 Updatebeta_2
WordpressWordpress Version0.6.2.1
WordpressWordpress Version0.6.2.1 Updatebeta_2
WordpressWordpress Version0.7
WordpressWordpress Version0.71
WordpressWordpress Version0.71-gold
WordpressWordpress Version0.72
WordpressWordpress Version0.72 Updatebeta1
WordpressWordpress Version0.72 Updatebeta2
WordpressWordpress Version0.72 Updaterc1
WordpressWordpress Version0.711
WordpressWordpress Version1.0
WordpressWordpress Version1.0-platinum
WordpressWordpress Version1.0.1
WordpressWordpress Version1.0.1-miles
WordpressWordpress Version1.0.2
WordpressWordpress Version1.0.2-blakey
WordpressWordpress Version1.2
WordpressWordpress Version1.2 Updatebeta
WordpressWordpress Version1.2-delta
WordpressWordpress Version1.2-mingus
WordpressWordpress Version1.2.1
WordpressWordpress Version1.2.2
WordpressWordpress Version1.3.1
WordpressWordpress Version1.4
WordpressWordpress Version1.5
WordpressWordpress Version1.5-strayhorn
WordpressWordpress Version1.5.1
WordpressWordpress Version1.5.1.1
WordpressWordpress Version1.5.1.2
WordpressWordpress Version1.5.1.3
WordpressWordpress Version1.5.2
WordpressWordpress Version1.6
WordpressWordpress Version2.0
WordpressWordpress Version2.0.1
WordpressWordpress Version2.0.2
WordpressWordpress Version2.0.3
WordpressWordpress Version2.0.4
WordpressWordpress Version2.0.5
WordpressWordpress Version2.0.6
WordpressWordpress Version2.0.7
WordpressWordpress Version2.0.8
WordpressWordpress Version2.0.9
WordpressWordpress Version2.0.10
WordpressWordpress Version2.0.10_rc1
WordpressWordpress Version2.0.10_rc2
WordpressWordpress Version2.0.11
WordpressWordpress Version2.1
WordpressWordpress Version2.1 Updatealpha_3
WordpressWordpress Version2.1.1
WordpressWordpress Version2.1.2
WordpressWordpress Version2.1.3
WordpressWordpress Version2.1.3_rc1
WordpressWordpress Version2.1.3_rc2
WordpressWordpress Version2.2
WordpressWordpress Version2.2.0
WordpressWordpress Version2.2.1
WordpressWordpress Version2.2.2
WordpressWordpress Version2.2.3
WordpressWordpress Version2.2_revision5002
WordpressWordpress Version2.2_revision5003
WordpressWordpress Version2.3
WordpressWordpress Version2.3 Updatebeta3
WordpressWordpress Version2.3 Updaterc1
WordpressWordpress Version2.3.1
WordpressWordpress Version2.3.1 Updaterc1
WordpressWordpress Version2.3.2
WordpressWordpress Version2.3.3
WordpressWordpress Version2.5
WordpressWordpress Version2.5.1
WordpressWordpress Version2.6
WordpressWordpress Version2.6.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.16% 0.865
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.