Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress "wp-admin/vars.php" 跨站脚本攻击漏洞
Vulnerability Description
WordPress 2.0.10 RC之前版本和2.1系列中2.1.3 RC2之前版本的wp-admin/vars.php中存在跨站脚本攻击漏洞。拥有主题特权的远程认证用户可以借助管理界面中的PATH_INFO,注入任意的web脚本或HTML。该漏洞与丢失PHP_SELF的常规表述处理有关。
CVSS Information
N/A
Vulnerability Type
N/A