CVE-2008-4733
WP Comment Remix <= 1.4.3 - SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) replytotext, (2) quotetext, (3) originallypostedby, (4) sep, (5) maxtags, (6) tagsep, (7) tagheadersep, (8) taglabel, and (9) tagheaderlabel parameters.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en wpcommentremix.php en el plugin WP Comment Remix versiones anteriores a v1.4.4 para WordPress permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante los parámetros (1) "replytotext", (2) "quotetext", (3) "originallypostedby", (4) sep, (5) "maxtags", (6) "tagsep", (7) tagheadersep, (8) "taglabel", y (9) "tagheaderlabel".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-10-14 CVE Published
- 2008-10-24 CVE Reserved
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://chxsecurity.org/advisories/adv-3-full.txt | X_refsource_misc | |
http://securityreason.com/securityalert/4492 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/497313/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45861 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/31750 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/32253 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pressography Search vendor "Pressography" | Wp Comment Remix Plugin Search vendor "Pressography" for product "Wp Comment Remix Plugin" | <= 1.4.3 Search vendor "Pressography" for product "Wp Comment Remix Plugin" and version " <= 1.4.3" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | * | - |
Safe
|
Pressography Search vendor "Pressography" | Wp Comment Remix Plugin Search vendor "Pressography" for product "Wp Comment Remix Plugin" | 1.4 Search vendor "Pressography" for product "Wp Comment Remix Plugin" and version "1.4" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | * | - |
Safe
|