|
|
| |
|
| |
wordpress: cross-site scripting
| Package(s): | wordpress |
CVE #(s): | CVE-2012-0287
|
| Created: | January 17, 2012 |
Updated: | January 18, 2012 |
| Description: |
From the CVE entry:
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature. |
| Alerts: |
|
( Log in to post comments)
|
|
|