Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-5490
Description:Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp- admin/includes/class-theme-installer-skin.php.
Test IDs: 1.3.6.1.4.1.25623.1.0.890813  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-5490
BugTraq ID: 95402
http://www.securityfocus.com/bid/95402
Debian Security Information: DSA-3779 (Google Search)
http://www.debian.org/security/2017/dsa-3779
https://wpvulndb.com/vulnerabilities/8718
https://www.mehmetince.net/low-severity-wordpress/
http://www.openwall.com/lists/oss-security/2017/01/14/6
http://www.securitytracker.com/id/1037591




© 1998-2025 E-Soft Inc. All rights reserved.