CVE-2011-5193

Phpace Samswhois < 1.4.2.3 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php, a different vulnerability than CVE-2011-5194.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Atmon3r · textwebappsphp
https://www.exploit-db.com/exploits/36488

Scores

EPSS 0.0132
EPSS Percentile 79.7%

Classification

CWE
CWE-79
Status published

Affected Products (3)

phpace/samswhois < 1.4.2.3
phpace/samswhois
n/a/n/a

Timeline

Published Sep 23, 2012
Tracked Since Feb 18, 2026