CVE-2012-1068
N/A
N/A
Summary
Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://plugins.trac.wordpress.org/changeset/416723/wp-recentcomments/trunk/core.php?old=316325&old_path=wp-recentcomments%2Ftrunk%2Fcore.php
- http://www.securityfocus.com/bid/49734
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70003
- http://wordpress.org/extend/plugins/wp-recentcomments/changelog/
- http://www.osvdb.org/75635
- http://secunia.com/advisories/46141
References
- http://plugins.trac.wordpress.org/changeset/416723/wp-recentcomments/trunk/core.php?old=316325&old_path=wp-recentcomments%2Ftrunk%2Fcore.php
- http://www.securityfocus.com/bid/49734
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70003
- http://wordpress.org/extend/plugins/wp-recentcomments/changelog/
- http://www.osvdb.org/75635
- http://secunia.com/advisories/46141
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.