CVE-2010-4747
WordPress Processing Embed <= 0.5.1 - Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en wordpress-processing-embed/data/popup.php del plugin Processing Embed 0.5 de WordPress. Permite a usuarios remotos inyectar codigo de script web o código HTML de su elección a través del parámetro pluginurl.
Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-12-08 CVE Published
- 2010-12-08 First Exploit
- 2011-03-01 CVE Reserved
- 2023-03-20 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/63761 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/35066 | 2010-12-08 | |
http://secunia.com/advisories/42545 | 2024-08-07 | |
http://www.johnleitch.net/Vulnerabilities/WordPress.Processing.Embed.0.5.Reflected.Cross-site.Scripting/65 | 2024-08-07 | |
http://www.osvdb.org/69764 | 2024-08-07 | |
http://www.securityfocus.com/bid/45266 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ahmattox Search vendor "Ahmattox" | Processing Embed Plugin Search vendor "Ahmattox" for product "Processing Embed Plugin" | 0.5 Search vendor "Ahmattox" for product "Processing Embed Plugin" and version "0.5" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | * | - |
Safe
|