MEDIUM
wordpress-mu: XSS vulnerability in helper function for WPMU
Published Mar 20, 2009
4.3
MEDIUMCVSS 2.0
EPSS 4.66%
Description
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
Affected products
No data.
OR
- ≤ 2.6
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.1
- 1.1.1
- 1.2
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.4
- 1.2.5a
- 1.3
- 1.3.1
- 1.3.2
- 1.3.3
- 1.5
- 1.5.1
- 2.6.1
- 2.6.2
- 2.6.3
- 2.6.5
- 2.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://marc.info/?l=bugtraq&m=126996727024732&w=2 vendor-advisoryx_refsource_HP
- http://www.securityfocus.com/archive/1/501667/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/34075 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1021838 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2009-1030 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=491318 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1031 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49184 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-1030
- https://www.cve.org/CVERecord?id=CVE-2009-1030
- https://www.exploit-db.com/exploits/8196 exploitx_refsource_EXPLOIT-DB
| Link | Providers | Tags |
|---|---|---|
| http://marc.info/?l=bugtraq&m=126996727024732&w=2 | vendor-advisoryx_refsource_HP | |
| http://www.securityfocus.com/archive/1/501667/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/34075 | vdb-entryx_refsource_BID | |
| http://www.securitytracker.com/id?1021838 | vdb-entryx_refsource_SECTRACK | |
| https://access.redhat.com/security/cve/CVE-2009-1030 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=491318 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1031 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/49184 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-1030 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-1030 | ||
| https://www.exploit-db.com/exploits/8196 | exploitx_refsource_EXPLOIT-DB |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 20, 2009
Updated Aug 7, 2024
Reserved Mar 19, 2009
Link CVE-2009-1030
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-1031 Assigner mitre
Published Mar 20, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-1031