4.3
CVE-2011-5192
- EPSS 0.38%
- Veröffentlicht 23.09.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Pretty Link Lite < 1.5.6 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5191.
Mögliche Gegenmaßnahme
Pretty Link Lite: Update to version 1.5.6, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Pretty Link Lite
Version
[*, 1.5.6)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Blairwilliams ≫ Pretty Link Lite Plugin Version <= 1.5.5
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.12
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.13
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.14
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.15
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.16
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.17
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.18
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.19
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.20
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.21
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.22
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.23
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.24
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.25
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.26
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.27
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.28
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.29
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.30
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.31
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.32
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.33
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.34
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.35
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.36
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.38
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.39
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.41
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.42
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.43
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.44
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.45
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.46
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.47
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.48
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.49
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.50
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.51
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.52
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.53
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.55
Blairwilliams ≫ Pretty Link Lite Plugin Version1.4.56
Blairwilliams ≫ Pretty Link Lite Plugin Version1.5.0
Blairwilliams ≫ Pretty Link Lite Plugin Version1.5.1
Blairwilliams ≫ Pretty Link Lite Plugin Version1.5.2
Blairwilliams ≫ Pretty Link Lite Plugin Version1.5.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.563 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.