Record summary

CVE-2007-4104 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin WP-FeedStats 2.1 - HTML InjectionExploitDB exploitby David KierznowskiNot analyzed1 file
ExploitDB

PoC details

References

9