Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form.
References
Link | Resource |
---|---|
http://websecurity.com.ua/1535/ | |
http://osvdb.org/43444 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-01-09 16:46
Updated : 2008-11-14 23:06
NVD link : CVE-2007-6677
Mitre link : CVE-2007-6677
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
peters_software
- random_anti-spam_image
wordpress
- wordpress