CVE-2008-5278
CVE-2008-5278
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://osvdb.org/50214http://secunia.com/advisories/32882http://secunia.com/advisories/32966http://securityreason.com/securityalert/4662https://exchange.xforce.ibmcloud.com/vulnerabilities/46882https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00000.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-December/msg00176.htmlhttp://wordpress.org/development/2008/11/wordpress-265/http://www.securityfocus.com/archive/1/498652http://www.securityfocus.com/bid/32476