Multiple Cross-Site Scripting Vulnerabilities in Sniplets Plugin for WordPress
CVE-2008-1061
Currently unrated
Summary
The Sniplets plugin for WordPress is susceptible to multiple Cross-Site Scripting (XSS) vulnerabilities, which allow remote attackers to inject arbitrary web script or HTML. This exploitation can occur through various parameters including 'text' in files such as warning.php, notice.php, and inset.php, as well as the 'url' parameter in view/admin/submenu.php and the 'page' parameter in view/admin/pager.php. Attackers may leverage these vulnerabilities to conduct malicious activities on affected websites, potentially leading to data theft or site defacement.
References
Timeline
Vulnerability published
Vulnerability Reserved