Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 18 Aug 2009 16:45:45 -0400 (EDT)
From: "Steven M. Christey" <>
cc: "Steven M. Christey" <>
Subject: Re: CVE Request -- WordPress

On Tue, 21 Jul 2009, Jan Lieskovsky wrote:

>   latest WordPress 2.8.2 version has addressed a XSS vulnerability:
>     XSS via unescaped HTML URLs as author comments in the admin page

Name: CVE-2009-2851
Status: Candidate
Reference: MLIST:[oss-security] 20090721 CVE Request -- WordPress
Reference: URL:
Reference: CONFIRM:
Reference: CONFIRM:
Reference: CONFIRM:
Reference: FEDORA:FEDORA-2009-8109
Reference: URL:
Reference: FEDORA:FEDORA-2009-8114
Reference: URL:
Reference: SECTRACK:1022589
Reference: URL:

Cross-site scripting (XSS) vulnerability in the administrator
interface in WordPress before 2.8.2 allows remote attackers to inject
arbitrary web script or HTML via a comment author URL.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.