Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form.
References
Link | Resource |
---|---|
http://osvdb.org/43444 | Broken Link |
http://websecurity.com.ua/1535/ | Third Party Advisory |
http://osvdb.org/43444 | Broken Link |
http://websecurity.com.ua/1535/ | Third Party Advisory |
Configurations
History
21 Nov 2024, 00:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/43444 - Broken Link | |
References | () http://websecurity.com.ua/1535/ - Third Party Advisory |
02 Aug 2023, 16:16
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://websecurity.com.ua/1535/ - Third Party Advisory | |
References | (OSVDB) http://osvdb.org/43444 - Broken Link | |
CPE | cpe:2.3:a:peters_software:random_anti-spam_image:*:*:*:*:*:*:*:* |
cpe:2.3:a:peters_software:random_anti-spam_image:*:*:*:*:*:wordpress:*:* |
Information
Published : 2008-01-10 00:46
Updated : 2024-11-21 00:40
NVD link : CVE-2007-6677
Mitre link : CVE-2007-6677
CVE.ORG link : CVE-2007-6677
JSON object : View
Products Affected
peters_software
- random_anti-spam_image
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')