Show filters
11 Total Results
Displaying 11-11 of 11
Sort by:
Attacker Value
Unknown
CVE-2007-4893
Disclosure Date: September 14, 2007 (last updated October 04, 2023)
wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.
0