/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2007-2627

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2007-2627

CGA ID

CGA-3554-hxc6-jjgw

Description

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.

References

  • https://images.chainguard.dev/security/CGA-3554-hxc6-jjgw

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images