Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-0193

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2008-0193
Last Modified 05 Sep 2008 05:34:26
Published 09 Jan 2008 07:46:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-0193

Summary

Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.

Vulnerable Systems

Application

  • Wordpress 2.0.11

  • Wordpress 2.1

  • Wordpress 2.1.1

  • Wordpress 2.1.2

  • Wordpress 2.1.3

  • Wordpress 2.1.3 Rc1

  • Wordpress 2.1.3 Rc2

  • Wordpress 2.2

  • Wordpress 2.2 Revision5002

  • Wordpress 2.2 Revision5003

  • Wordpress 2.2.0

  • Wordpress 2.2.1

  • Wordpress 2.2.2

  • Wordpress 2.2.3

  • Wordpress 2.3


References

BID - 27123

BUGTRAQ - 20080103 securityvulns.com russian vulnerabilities digest

MISC - http://websecurity.com.ua/1676/

MISC - http://securityvulns.ru/Sdocument755.html

DEBIAN - DSA-1502

SREASON - 3539

SECUNIA - 29014


Last Updated: 27 May 2016 10:46:42