CVE-2008-0193: XSS
Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0193?
CVE-2008-0193 is classified as a moderate severity vulnerability due to potential remote code execution via cross-site scripting.
How do I fix CVE-2008-0193?
To fix CVE-2008-0193, upgrade WordPress to version 2.0.12 or later, or apply appropriate security patches.
What systems are affected by CVE-2008-0193?
CVE-2008-0193 affects WordPress versions 2.0.11 and earlier, as well as 2.1.x through 2.3.x.
Can CVE-2008-0193 be exploited remotely?
Yes, CVE-2008-0193 can be exploited remotely by injecting malicious scripts through the backup parameter.
What kind of attack can CVE-2008-0193 lead to?
CVE-2008-0193 can lead to cross-site scripting attacks, allowing attackers to execute arbitrary web scripts in users' browsers.