CVE-2007-1622
WordPress < 2.0.10 RC2 and < 2.1.3 RC2 - Authenticated Cross-Site Scripting via PATH_INFO
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1622. PoCs published by Alexander Concha.
AI-analyzed exploit summary This is a proof-of-concept for a cross-site scripting (XSS) vulnerability in WordPress. It demonstrates how an attacker can inject malicious JavaScript into a form submission to execute arbitrary code in the context of a user's browser session.
Description
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF.
Exploits (1)
This is a proof-of-concept for a cross-site scripting (XSS) vulnerability in WordPress. It demonstrates how an attacker can inject malicious JavaScript into a form submission to execute arbitrary code in the context of a user's browser session.