CVE-2007-5710
2.6
CVSS SCORE
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N
Description
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
High
Confidentiality
None
Integrity
P
Availability
None
Affected Software Configurations
- a wordpress wordpress 2.3 * * * * * * *
Weaknesses (CWE)
- CWE-79
References & External Links
- http://osvdb.org/38279
- http://secunia.com/advisories/27407
- http://wordpress.org/development/2007/10/wordpress-231/
- http://www.securityfocus.com/archive/1/482905/100/0/threaded
- http://www.securityfocus.com/bid/26228
- http://www.vupen.com/english/advisories/2007/3640
- http://www.waraxe.us/advisory-59.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38166
- http://osvdb.org/38279
- http://secunia.com/advisories/27407
- http://wordpress.org/development/2007/10/wordpress-231/
- http://www.securityfocus.com/archive/1/482905/100/0/threaded
- http://www.securityfocus.com/bid/26228
- http://www.vupen.com/english/advisories/2007/3640
- http://www.waraxe.us/advisory-59.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38166