CVE-2009-1030
WordPress MU < 2.7 - Cross-Site Scripting via HTTP Host Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1030. PoCs published by Juan Galiana Lara.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in WordPress MU < 2.7 due to improper sanitization of the HTTP Host header. The PoC shows how an attacker can inject malicious JavaScript via the Host header, which executes in the victim's browser context.
Description
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
Exploits (1)
This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in WordPress MU < 2.7 due to improper sanitization of the HTTP Host header. The PoC shows how an attacker can inject malicious JavaScript via the Host header, which executes in the victim's browser context.