Vulnerabilities in Wordpress, which can be exploited by malicious people to
conduct cross-site scripting and script insertion attacks.Input passed to
certain parameters in various scripts isn't properly verified before it is
returned to the user. This can be exploited to execute arbitrary HTML or
script code in a user's browser session in context of an affected site by
tricking the user into visiting a malicious website or follow a specially
crafted link.
An attacker may leverage these issues to execute arbitrary script code in
the browser of an unsuspecting user in the context of the affected site.
This may allow the attacker to steal cookie-based authentication
credentials and to launch other attacks.
Hackers Center Security Group (http://www.hackerscenter.com)
Credit: DoZ Class: Input Validation Error
Remote: Yes
Product: WordPress
Version: 2.3.2
Vendor: http://www.WordPress.com
Attackers can exploit these issues via a web client.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Maksymilian Arciemowicz discovered a Integer Overflow
vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.