CVE-2006-1796 Information

Description

Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2 and possibly other versions before 2.0.1 allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER[‘REQUEST_URI’]).

Reference

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=328909 http://trac.wordpress.org/ticket/1686

Share on: