| Vulnerability Name: | CVE-2007-3240 (CCN-34917) | ||||||||
| Assigned: | 2007-06-08 | ||||||||
| Published: | 2007-06-08 | ||||||||
| Updated: | 2018-10-16 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in 404.php in the Vistered-Little theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI) that accesses index.php. Note: this can be leveraged for PHP code execution in an administrative session. | ||||||||
| CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:H/RL:U/RC:UR)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Fri Jun 08 2007 - 08:15:38 CDT Wordpress default theme XSS (admin) and other problems Source: MITRE Type: CNA CVE-2007-3240 Source: OSVDB Type: UNKNOWN 37441 Source: SREASON Type: UNKNOWN 2807 Source: CCN Type: WordPress Web site WordPress Source: CCN Type: OSVDB ID: 37441 Vistered-Little Theme for WordPress 404.php REQUEST_URI XSS Source: BUGTRAQ Type: UNKNOWN 20070608 Wordpress default theme XSS (admin) and other problems Source: CCN Type: BID-24383 WordPress Request_URI Parameter Cross-Site Scripting Vulnerability Source: MISC Type: UNKNOWN http://www.xssnews.com/ Source: XF Type: UNKNOWN wordpress-404-xss(34917) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||