LWN.net Logo

wordpress: cross-site scripting

Package(s):wordpress CVE #(s):CVE-2012-0287
Created:January 17, 2012 Updated:January 18, 2012
Description: From the CVE entry:

Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.

Alerts:
Fedora FEDORA-2012-0248 2012-01-07
Fedora FEDORA-2012-0247 2012-01-07
Mageia MGASA-2012-0168 2012-07-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds