CVE-2011-5019

Textpattern - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the ddb parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jonathan Claudius · textwebappsphp
https://www.exploit-db.com/exploits/36489

Scores

EPSS 0.0302
EPSS Percentile 86.5%

Classification

CWE
CWE-79
Status published

Affected Products (2)

textpattern/textpattern
n/a/n/a

Timeline

Published Jan 05, 2012
Tracked Since Feb 18, 2026