blogsecurity.net
http://blogsecurity.net/news/news-130707 CVE-2007-4104
WordPress Plugin WP-FeedStats 2.1 - HTML Injection
Record summary
CVE-2007-4104 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin WP-FeedStats 2.1 - HTML InjectionExploitDB exploitby David KierznowskiNot analyzed1 file
References
9blogsecurity.net
http://blogsecurity.net/wordpress/news-260707 bueltge.deConfirmation
http://bueltge.de/plugin-wp-feedstats-in-neuer-version/481 20070726 WordPress wp-feedstats persistent XSSmailing list
http://marc.info/?l=full-disclosure&m=118548811323718&w=2 37259vdb entry
http://osvdb.org/37259 26249Third-party advisory
http://secunia.com/advisories/26249 25085vdb entry
http://www.securityfocus.com/bid/25085 wordpress-wpfeedstats-xss(35646)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35646 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4104