CVE-2009-1030
20.03.2009, 00:30
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
Vendor | Product | Version |
---|---|---|
wordpress | wordpress_mu | 𝑥 ≤ 2.6 |
wordpress | wordpress_mu | 1.0 |
wordpress | wordpress_mu | 1.0:rc1 |
wordpress | wordpress_mu | 1.0:rc2 |
wordpress | wordpress_mu | 1.0:rc3 |
wordpress | wordpress_mu | 1.0:rc4 |
wordpress | wordpress_mu | 1.1 |
wordpress | wordpress_mu | 1.1.1 |
wordpress | wordpress_mu | 1.2 |
wordpress | wordpress_mu | 1.2.1 |
wordpress | wordpress_mu | 1.2.2 |
wordpress | wordpress_mu | 1.2.3 |
wordpress | wordpress_mu | 1.2.4 |
wordpress | wordpress_mu | 1.2.4:rc1 |
wordpress | wordpress_mu | 1.2.5a:a |
wordpress | wordpress_mu | 1.3 |
wordpress | wordpress_mu | 1.3.1 |
wordpress | wordpress_mu | 1.3.2 |
wordpress | wordpress_mu | 1.3.3 |
wordpress | wordpress_mu | 1.5:rc1 |
wordpress | wordpress_mu | 1.5.1 |
wordpress | wordpress_mu | 2.6.1 |
wordpress | wordpress_mu | 2.6.2 |
wordpress | wordpress_mu | 2.6.3 |
wordpress | wordpress_mu | 2.6.5 |
wordpress | wordpress_mu | 2.7 |
𝑥
= Vulnerable software versions
References