CVE-2011-3865
28.09.2011, 10:55
Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
| Vendor | Product | Version |
|---|---|---|
| ulyssesonline | black-letterhead | 𝑥 ≤ 1.5 |
| ulyssesonline | black-letterhead | 1.1 |
| ulyssesonline | black-letterhead | 1.2 |
| ulyssesonline | black-letterhead | 1.3 |
| ulyssesonline | black-letterhead | 1.4 |
𝑥
= Vulnerable software versions