First published: Thu Jan 10 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cryptwidth, (2) cryptheight, (3) bgimg, (4) charR, (5) charG, (6) charB, (7) charclear, (8) tfont, (9) charel, (10) charelc, (11) charelv, (12) charnbmin, (13) charnbmax, (14) charspace, (15) charsizemin, (16) charsizemax, (17) charanglemax, (18) noisepxmin, (19) noisepxmax, (20) noiselinemin, (21) noiselinemax, (22) nbcirclemin, (23) nbcirclemax, or (24) brushsize parameter to wp-admin/options-general.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wordpress Cryptographp | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-0203 is considered to be moderate due to its exploitation potential through multiple XSS vulnerabilities.
To fix CVE-2008-0203, you should update the Cryptographp plugin to version 1.3 or later.
CVE-2008-0203 contains multiple cross-site scripting (XSS) vulnerabilities that allow for arbitrary script injection.
Cryptographp versions 1.2 and earlier are affected by CVE-2008-0203.
Yes, remote attackers can exploit CVE-2008-0203 to inject arbitrary web scripts or HTML into affected sites.