Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16260
HistoryMar 05, 2007 - 12:00 a.m.

Wordpress <= v2.1.0

2007-03-0500:00:00
vulners.com
30

If you're logged in into wordpress as an admin, your comments aren't properly sanitized, thus allowing an XSS to be posted. This can be exploited using XSRF techniques.

More info & PoC: http://www.virtuax.be/advisories/Advisory4-20022007.txt