[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] CVE-request: WordPress advanced-text-widget XSS
From:       Kurt Seifried <kseifried () redhat ! com>
Date:       2011-12-19 17:37:31
Message-ID: 4EEF765B.8030700 () redhat ! com
[Download RAW message or body]

On 12/18/2011 02:45 AM, Henri Salo wrote:
> Can I get CVE-identifier for this issue?
> 
> Original report: http://seclists.org/bugtraq/2011/Nov/133
> Vendor report: http://wordpress.org/support/topic/wordpress-advanced-text-widget-plugin-cross-site-scripting-vulnerabilities
>  Fixed in 2.0.2
> Vulnerable versions: 2.0.1 and all below
> One example: advancedtext.php?page=
> 
> http://wordpress.org/extend/plugins/advanced-text-widget/changelog/
> ------------------------------------------------------------------------
> r466102 | maxchirkov | 2011-11-22 19:32:02 +0200 (Tue, 22 Nov 2011) | 2 lines
> 
> Committing version 2.0.2
> - Updated all instances of $_GET method with esc_attr() to improve security.
> ------------------------------------------------------------------------
> 
> - Henri Salo
Please use CVE-2011-4618 for this issue.

-- 

-Kurt Seifried / Red Hat Security Response Team


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic