Multiple Cross-Site Scripting Vulnerabilities in Sniplets Plugin for WordPress
CVE-2008-1061

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
28 February 2008

Summary

The Sniplets plugin for WordPress is susceptible to multiple Cross-Site Scripting (XSS) vulnerabilities, which allow remote attackers to inject arbitrary web script or HTML. This exploitation can occur through various parameters including 'text' in files such as warning.php, notice.php, and inset.php, as well as the 'url' parameter in view/admin/submenu.php and the 'page' parameter in view/admin/pager.php. Attackers may leverage these vulnerabilities to conduct malicious activities on affected websites, potentially leading to data theft or site defacement.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.