CVE-2007-4153
WordPress Core <= 2.2.1 - Authenticated (Admin+) Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the Options Database Table in the Admin Panel, accessed through options.php; or (2) the opml_url parameter to link-import.php. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en WordPress 2.2.1 permiten a administradores autenticados remotamente inyectar secuencias de comandos web o HTML de su elección a través de (2) la tabla Options de la base de datos en el Panel de Administración, accedida a través de options.php;o (2) el parámetro opml_url de link-import.php. NOTA: esto podría no cruzar fronteras de privilegios en algunas configuraciones, puesto que el rol de Administrador tiene la capacidad unfiltered_html.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-08-03 CVE Reserved
- 2007-08-03 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-09-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://codex.wordpress.org/Roles_and_Capabilities | X_refsource_misc | |
http://osvdb.org/46994 | Vdb Entry | |
http://osvdb.org/46995 | Vdb Entry | |
http://secunia.com/advisories/30013 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35720 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35722 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://mybeni.rootzilla.de/mybeNi/2007/wordpress_zeroday_vulnerability_roundhouse_kick_and_why_i_nearly_wrote_the_first_blog_worm | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2008/dsa-1564 | 2017-07-29 |