CVE Database
/

CVE-2007-3239

Back to search

CVE-2007-3239

Published: Jun 15, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in searchform.php in the AndyBlue theme before 20070607 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

VendorProductVersions

n/a

n/a

affected
n/a

References

24490
vdb-entry
x_refsource_BID
36379
vdb-entry
x_refsource_OSVDB
2807
third-party-advisory
x_refsource_SREASON
http://www.xssnews.com/
x_refsource_MISC
25659
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now