4.3

CVE-2011-5192

Exploit

Pretty Link Lite < 1.5.6 - Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5191.
Mögliche Gegenmaßnahme
Pretty Link Lite: Update to version 1.5.6, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Pretty Link Lite
Version [*, 1.5.6)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BlairwilliamsPretty Link Lite Plugin Version <= 1.5.5
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.12
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.13
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.14
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.15
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.16
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.17
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.18
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.19
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.20
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.21
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.22
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.23
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.24
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.25
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.26
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.27
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.28
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.29
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.30
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.31
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.32
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.33
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.34
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.35
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.36
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.38
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.39
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.41
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.42
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.43
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.44
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.45
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.46
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.47
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.48
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.49
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.50
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.51
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.52
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.53
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.55
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.4.56
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.5.0
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.5.1
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.5.2
   WordpressWordpress Version-
BlairwilliamsPretty Link Lite Plugin Version1.5.4
   WordpressWordpress Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.563
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.