CVE-2008-5278: XSS
Cross-site scripting (XSS) vulnerability in the selflink function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTPHOST variable).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5278?
The severity of CVE-2008-5278 is considered medium due to its potential for cross-site scripting attacks.
How do I fix CVE-2008-5278?
To fix CVE-2008-5278, update your WordPress installation to version 2.6.5 or later.
What versions of WordPress are affected by CVE-2008-5278?
CVE-2008-5278 affects WordPress versions prior to 2.6.5, including all versions from 0.6.2 to 2.6.4.
What is the nature of the vulnerability in CVE-2008-5278?
CVE-2008-5278 involves a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary scripts via the Host header.
Can CVE-2008-5278 be exploited remotely?
Yes, CVE-2008-5278 can be exploited remotely by attackers who can manipulate the Host header.