First published: Wed Oct 22 2008(Updated: )
Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | ||
WordPress | =1.0 | |
WordPress | =1.2.2 | |
WordPress | =1.2.3 | |
WordPress | =1.3 | |
WordPress | =1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4671 has a moderate severity level due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2008-4671, upgrade WordPress MU to a version later than 2.6.
CVE-2008-4671 affects WordPress MU versions prior to 2.6.
CVE-2008-4671 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2008-4671 can allow attackers to inject arbitrary web scripts, potentially leading to unauthorized access.