CVE-2011-5264
Lazyest Backup < 0.2.2 - Reflected Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in lazyest-backup.php in the Lazyest Backup plugin before 0.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xml_or_all parameter.
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en lazyest-backup.php en el Lazyest Backup plugin anterior a v0.2.2 para WordPress, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro xml_or_all.
The Lazyest Backup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'xml_or_all' parameter found in the lazyest-backup.php file in versions up to 0.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-12-05 CVE Published
- 2013-02-12 CVE Reserved
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.osvdb.org/77493 | Vdb Entry | |
http://www.securityfocus.com/bid/50900 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/71650 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://plugins.trac.wordpress.org/changeset?reponame=&new=470737%40lazyest-backup&old=468541%40lazyest-backup | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://wordpress.org/extend/plugins/lazyest-backup/changelog | 2017-08-29 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/47092 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Marcel Brinkkemper Search vendor "Marcel Brinkkemper" | Lazyest-backup Search vendor "Marcel Brinkkemper" for product "Lazyest-backup" | <= 0.2.1 Search vendor "Marcel Brinkkemper" for product "Lazyest-backup" and version " <= 0.2.1" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Marcel Brinkkemper Search vendor "Marcel Brinkkemper" | Lazyest-backup Search vendor "Marcel Brinkkemper" for product "Lazyest-backup" | 0.1.0 Search vendor "Marcel Brinkkemper" for product "Lazyest-backup" and version "0.1.0" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Marcel Brinkkemper Search vendor "Marcel Brinkkemper" | Lazyest-backup Search vendor "Marcel Brinkkemper" for product "Lazyest-backup" | 0.2.0 Search vendor "Marcel Brinkkemper" for product "Lazyest-backup" and version "0.2.0" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|