LWN.net Logo

wordpress: cross-site scripting

Package(s):wordpress CVE #(s):CVE-2008-5278
Created:December 3, 2008 Updated:December 22, 2008
Description:

From the Red Hat bugzilla entry:

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

Alerts:
Fedora FEDORA-2008-11104 2008-12-22
Fedora FEDORA-2008-10482 2008-12-03
Fedora FEDORA-2008-10483 2008-12-03
Fedora FEDORA-2008-10468 2008-12-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds