Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-9031
Description:Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2015.236   1.3.6.1.4.1.25623.1.0.703085  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-9031
BugTraq ID: 71237
http://www.securityfocus.com/bid/71237
Debian Security Information: DSA-3085 (Google Search)
http://www.debian.org/security/2014/dsa-3085
http://seclists.org/fulldisclosure/2014/Nov/62
http://www.mandriva.com/security/advisories?name=MDVSA-2014:233
http://klikki.fi/adv/wordpress.html
http://openwall.com/lists/oss-security/2014/11/25/12
http://www.securitytracker.com/id/1031243




© 1998-2025 E-Soft Inc. All rights reserved.