Search

published date: May 2, 2005

CVE-2005-1102 : Cross-Site Scripting Vulnerability

Description

Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.

Product(s):

  • WordPress
  • WordPress 0.711
  • WordPress 0.71
  • WordPress 0.71 Beta3

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2005-1102, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2005-1102 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?