Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-5278
Description:Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
Test IDs: 1.3.6.1.4.1.25623.1.0.62816   1.3.6.1.4.1.25623.1.0.62808   1.3.6.1.4.1.25623.1.0.61954   1.3.6.1.4.1.25623.1.0.860823   1.3.6.1.4.1.25623.1.0.62812   1.3.6.1.4.1.25623.1.0.63008   1.3.6.1.4.1.25623.1.0.860318   1.3.6.1.4.1.25623.1.0.860769   1.3.6.1.4.1.25623.1.0.860881  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-5278
BugTraq ID: 32476
http://www.securityfocus.com/bid/32476
Bugtraq: 20081125 WordPress XSS vulnerability in RSS Feed Generator (Google Search)
http://www.securityfocus.com/archive/1/498652
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00176.html
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00000.html
http://osvdb.org/50214
http://secunia.com/advisories/32882
http://secunia.com/advisories/32966
http://securityreason.com/securityalert/4662
XForce ISS Database: wordpress-feed-xss(46882)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46882




© 1998-2025 E-Soft Inc. All rights reserved.