CVE-2008-0193
WordPress < 2.0.11 - Cross-Site Scripting via Backup Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0193. PoCs published by 3APA3A.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in WordPress by injecting a malicious script via the 'backup' parameter in the wp-db-backup.php page. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies.
Description
Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in WordPress by injecting a malicious script via the 'backup' parameter in the wp-db-backup.php page. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies.