Your submission was sent successfully! Close

CVE-2007-1894

Published: 09 April 2007

Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.

Priority

Unknown

Status

Package Release Status
wordpress
Launchpad, Ubuntu, Debian
Upstream Needs triage