[prev in list] [next in list] [prev in thread] [next in thread]
List: oss-security
Subject: Re: [oss-security] CVE-request: WordPress advanced-text-widget XSS
From: Kurt Seifried <kseifried () redhat ! com>
Date: 2011-12-19 17:37:31
Message-ID: 4EEF765B.8030700 () redhat ! com
[Download RAW message or body]
On 12/18/2011 02:45 AM, Henri Salo wrote:
> Can I get CVE-identifier for this issue?
>
> Original report: http://seclists.org/bugtraq/2011/Nov/133
> Vendor report: http://wordpress.org/support/topic/wordpress-advanced-text-widget-plugin-cross-site-scripting-vulnerabilities
> Fixed in 2.0.2
> Vulnerable versions: 2.0.1 and all below
> One example: advancedtext.php?page=
>
> http://wordpress.org/extend/plugins/advanced-text-widget/changelog/
> ------------------------------------------------------------------------
> r466102 | maxchirkov | 2011-11-22 19:32:02 +0200 (Tue, 22 Nov 2011) | 2 lines
>
> Committing version 2.0.2
> - Updated all instances of $_GET method with esc_attr() to improve security.
> ------------------------------------------------------------------------
>
> - Henri Salo
Please use CVE-2011-4618 for this issue.
--
-Kurt Seifried / Red Hat Security Response Team
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic