Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2015-1385

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2015-1385
Last Modified 04 Feb 2015 12:20:03
Published 02 Feb 2015 10:59:05
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2015-1385

Summary

Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a powerpress-editcategoryfeed action in the powerpressadmin_categoryfeeds.php page to wp-admin/admin.php.

Vulnerable Systems

Application

  • Blubrry Powerpress Podcasting 6.0


References

MISC - https://www.netsparker.com/cve-2015-1385-xss-vulnerability-in-blubrry-powerpress/

CONFIRM - https://wordpress.org/plugins/powerpress/changelog/

BID - 72362

BUGTRAQ - 20150129 Blubrry PowerPress Security Advisory - XSS Vulnerability - CVE-2015-1385

FULLDISC - 20150130 Blubrry PowerPress Security Advisory - XSS Vulnerability - CVE-2015-1385

MISC - http://packetstormsecurity.com/files/130155/Blubrry-PowerPress-6.0-Cross-Site-Scripting.html


Last Updated: 27 May 2016 11:07:41