WordPress2.0.0~authors’website~XSS attack
Posted by imei on February 15th, 2006——————-Summary—————-
Software: WordPress
Sowtware’s Web Site: http://www.wordpress.org
Versions: 2.0.0
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Available
Discovered by: imei addmimistrator
Risk Level: Low
—————–Description—————
There is some security bug in most poweful and common Blog Software, WordPress 2.0.0 (latest version) that allows attacker performe an XSS attack. bug is in result of poor checking quotations for user suplied variables in author’s website for not logged […]