LWN.net Logo

wordpress-mu: cross-site scripting vulnerability

Package(s):wordpress-mu CVE #(s):CVE-2009-1030
Created:April 9, 2009 Updated:August 18, 2009
Description: From the National Vulnerability Database entry: Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
Alerts:
Fedora FEDORA-2009-8538 2009-08-15
Fedora FEDORA-2009-3474 2009-04-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds