Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WordPress Multiple Input Validation Vulnerabilities

WordPress is prone to multiple input-validation vulnerabilities because the application fails to sanitize user-supplied input. These issues include multiple cross-site scripting vulnerabilities, an HTML-injection vulnerability, and multiple SQL-injection vulnerabilities.

A successful exploit may allow an attacker to steal cookie-based authentication credentials, execute malicious script code, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

WordPress 2.2.1 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus