CVE-2011-0641
StatPressCN <= 1.9.0 - Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/admin.php in the StatPressCN plugin 1.9.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) what1, (2) what2, (3) what3, (4) what4, and (5) what5 parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en wp-admin/admin.php del complemento StatPressCN para WordPress permite a atacantes remotos inyectar secuencias de comando o código HTML a través de los parámetros (1) what1, (2) what2, (3) what3, (4) what4, y (5) what5. NOTA:la procedencia de esta información es desconocida, los detalles son obtenidos exclusivamente de la información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-01-21 CVE Published
- 2011-01-25 CVE Reserved
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://osvdb.org/70595 | Vdb Entry | |
http://www.securityfocus.com/bid/45950 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/64882 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/43016 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Heart5 Search vendor "Heart5" | Statpresscn Search vendor "Heart5" for product "Statpresscn" | 1.9.0 Search vendor "Heart5" for product "Statpresscn" and version "1.9.0" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | * | - |
Safe
|