Vulnerability Name: | CVE-2007-4481 (CCN-36212) | ||||||||
Assigned: | 2007-08-17 | ||||||||
Published: | 2007-08-17 | ||||||||
Updated: | 2018-10-15 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in index.php in the (1) Blix 0.9.1 and (2) Blix 0.9.1 Rus themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
2.4 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4481 Source: CCN Type: Securityvulns Web site Vulnerability in theme Blix 0.9.1 for WordPress Source: MISC Type: UNKNOWN http://securityvulns.ru/Rdocument825.html Source: MISC Type: UNKNOWN http://websecurity.com.ua/1248/ Source: CCN Type: Blix theme for Wordpress Web site Blix Preview Source: CCN Type: OSVDB ID: 37298 Blix Rus Theme for WordPress index.php PATH_INFO Parameter XSS Source: BUGTRAQ Type: UNKNOWN 20070821 Vulnerabilities digest Source: XF Type: UNKNOWN blix-index-xss(36212) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |