Back to search
CVE-2007-4153
Published: Aug 3, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php; or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
wordpress-options-xss(35722)
vdb-entry
x_refsource_XF
http://codex.wordpress.org/Roles_and_Capabilities
x_refsource_MISC
30013
third-party-advisory
x_refsource_SECUNIA
wordpress-linkimport-xss(35720)
vdb-entry
x_refsource_XF
46995
vdb-entry
x_refsource_OSVDB
DSA-1564
vendor-advisory
x_refsource_DEBIAN
46994
vdb-entry
x_refsource_OSVDB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now