Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether this specific XSS scenario has security relevance
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2012-01-30T17:00:00Z
Updated: 2024-09-16T23:26:38.397Z
Reserved: 2012-01-18T00:00:00Z
Link: CVE-2012-0782
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-01-30T17:55:00.843
Modified: 2024-11-21T01:35:43.143
Link: CVE-2012-0782
Redhat
No data.