Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  XSS Remote In vCard 2.6 (c)2002

  Arbitrary file disclosure vulnerability in rrdbrowse <= 1.6

  LI-Guestbook SQL Injection Vulnerability

  Sava's GuestBook Multiple Vulnerabilities

From:ciri_(at)_virtuax.be <ciri_(at)_virtuax.be>
Date:05.03.2007
Subject:Wordpress <= v2.1.0

If you're logged in into wordpress as an admin, your comments aren't properly sanitized, thus allowing an XSS to be posted. This can be exploited using XSRF techniques.

More info & PoC: http://www.virtuax.be/advisories/Advisory4-20022007.txt

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server