PT-2006-1785 · WordPress+1 · Wordpress+1

CVE-2006-0733

·

Publicado

2006-02-16

·

Atualizado

2024-08-07

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WordPress version 2.0.0
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as onfocus and onblur in the "author's website" field. It is suggested that this issue might only be exploitable by the same user who injects the XSS.
Recommendations For WordPress version 2.0.0, consider restricting the use of scriptable attributes in the "author's website" field to minimize the risk of exploitation. As a temporary workaround, disabling the ability to input scriptable attributes such as onfocus and onblur in this field may help until a more permanent solution is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0733

Produtos afetados

Debian
Wordpress