CVE-2007-2627 Information

Share on:

Description

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress when custom 404 pages that call get_sidebar are used allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF) a different vulnerability than CVE-2007-1622.

Reference

http://osvdb.org/37296 http://securityreason.com/securityalert/2694 http://www.securityfocus.com/archive/1/467360/100/0/threaded