Cross-Site Scripting Vulnerability in WordPress MU by WordPress
CVE-2008-4671

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
22 October 2008

What is CVE-2008-4671?

This vulnerability allows remote attackers to exploit WordPress MU before version 2.6 by injecting arbitrary web scripts or HTML through the 's' and 'ip_address' parameters in the wp-admin/wp-blogs.php file. Successful exploitation can lead to unauthorized access and potential data compromise for users interacting with affected installations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2008-4671 : Cross-Site Scripting Vulnerability in WordPress MU by WordPress