Vulnerability Name: | CVE-2008-1061 (CCN-40830) | ||||||||
Assigned: | 2008-02-25 | ||||||||
Published: | 2008-02-25 | ||||||||
Updated: | 2018-10-11 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to (a) warning.php, (b) notice.php, and (c) inset.php in view/sniplets/, and possibly (d) modules/execute.php; the (2) url parameter to (e) view/admin/submenu.php; and the (3) page parameter to (f) view/admin/pager.php. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Feb 25 2008 - 10:46:50 CST Wordpress Plugin Sniplets 1.1.2 Multiple Vulnerabilities Source: MITRE Type: CNA CVE-2008-1061 Source: CCN Type: SA29099 WordPress Sniplets Plugin Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 29099 Source: SREASON Type: UNKNOWN 3706 Source: CCN Type: Urban Giraffe Web site Sniplets Plugin Source: CCN Type: OSVDB ID: 42254 Sniplets Plugin for WordPress view/sniplets/warning.php text Parameter XSS Source: CCN Type: OSVDB ID: 42255 Sniplets Plugin for WordPress view/sniplets/notice.php text Parameter XSS Source: CCN Type: OSVDB ID: 42256 Sniplets Plugin for WordPress view/sniplets/inset.php text Parameter XSS Source: CCN Type: OSVDB ID: 42257 Sniplets Plugin for WordPress view/admin/submenu.php url Parameter XSS Source: CCN Type: OSVDB ID: 42258 Sniplets Plugin for WordPress modules/execute.php text Parameter XSS Source: CCN Type: OSVDB ID: 42259 Sniplets Plugin for WordPress view/admin/pager.php page Parameter XSS Source: BUGTRAQ Type: UNKNOWN 20080225 Wordpress Plugin Sniplets 1.1.2 Multiple Vulnerabilities Source: BID Type: Exploit 27985 Source: CCN Type: BID-27985 WordPress Sniplets Plugin Multiple Input Validation Vulnerabilities Source: XF Type: UNKNOWN sniplets-multiple-xss(40830) Source: XF Type: UNKNOWN sniplets-multiple-xss(40830) Source: EXPLOIT-DB Type: UNKNOWN 5194 | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |