Your submission was sent successfully! Close

CVE-2007-1894

Published: 9 April 2007

Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.

Priority

Unknown

Status

Package Release Status
wordpress
Launchpad, Ubuntu, Debian
dapper Ignored
(reached end-of-life)
edgy Needed
(reached end-of-life)
feisty Not vulnerable

gutsy Not vulnerable

hardy Not vulnerable

intrepid Not vulnerable

jaunty Not vulnerable

karmic Not vulnerable

lucid Not vulnerable

upstream Needs triage