Secunia Logo
 
CVE Reference: CVE-2007-1732
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-1732

Description:
** DISPUTED ** Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stating that this is legitimate functionality for administrators. However, it has been patched by at least one vendor.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA24430
  Secunia Advisory: SA24566

OSVDB
  33884

MISC
  http://codex.wordpress.org/Roles_and_Capabilities

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=117319839710382&w=2


Return to the previous page.