CVE-2014-4603 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret (2) key or (3) appid parameter.
Reference
http://codevigilant.com/disclosure/wp-plugin-yahoo-updates-for-wordpress-a3-cross-site-scripting-xss http://www.securityfocus.com/bid/68401
Share on: