CVE-2010-5294: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the requestfilesystemcredentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-5294?
CVE-2010-5294 has a medium severity level due to its cross-site scripting vulnerabilities.
How do I fix CVE-2010-5294?
To fix CVE-2010-5294, update your WordPress installation to version 3.0.2 or later.
What versions of WordPress are affected by CVE-2010-5294?
CVE-2010-5294 affects multiple versions of WordPress prior to 3.0.2, including those as old as 2.0.
What type of vulnerability is CVE-2010-5294?
CVE-2010-5294 is categorized as a cross-site scripting (XSS) vulnerability.
Can exploiting CVE-2010-5294 lead to further attacks?
Yes, exploiting CVE-2010-5294 can allow attackers to inject arbitrary scripts, potentially leading to other attacks.