CVE-2007-4544
4.3
CVSS SCORE
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Description
Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).
CVSS Vector Details
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
P
Availability
None
Affected Software Configurations
- a wordpress wordpress_mu * * * * * * * *
Weaknesses (CWE)
- CWE-352
References & External Links
- http://osvdb.org/38442
- http://securityvulns.ru/Rdocument875.html
- http://websecurity.com.ua/1269/
- http://www.securityfocus.com/archive/1/482006/100/0/threaded
- http://osvdb.org/38442
- http://securityvulns.ru/Rdocument875.html
- http://websecurity.com.ua/1269/
- http://www.securityfocus.com/archive/1/482006/100/0/threaded