CVE-2011-5193

Phpace Samswhois < 1.4.2.3 - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php, a different vulnerability than CVE-2011-5194.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Atmon3r · textwebappsphp
https://www.exploit-db.com/exploits/36488

References (1)

Core 1
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47428

Scores

EPSS 0.0132
EPSS Percentile 80.0%

Details

CWE
CWE-79
Status published
Products (2)
phpace/samswhois 1.1
phpace/samswhois < 1.4.2.3
Published Sep 23, 2012
Tracked Since Feb 18, 2026