CVE Database
/

CVE-2007-4153

Back to search

CVE-2007-4153

Published: Aug 3, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php; or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

VendorProductVersions

n/a

n/a

affected
n/a

References

wordpress-options-xss(35722)
vdb-entry
x_refsource_XF
30013
third-party-advisory
x_refsource_SECUNIA
wordpress-linkimport-xss(35720)
vdb-entry
x_refsource_XF
46995
vdb-entry
x_refsource_OSVDB
DSA-1564
vendor-advisory
x_refsource_DEBIAN
46994
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now