Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3429

Опубликовано: 17 июн. 2015
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressfixed4.2.2+dfsg-1package
wordpressnot-affectedwheezypackage
wordpressnot-affectedsqueezepackage

Примечания

  • https://wordpress.org/news/2015/05/wordpress-4-2-2/

  • https://www.netsparker.com/cve-2015-3429-dom-xss-vulnerability-in-twenty-fifteen-wordpress-theme/

  • The default theme twentyfifteen is not present in wheezy. Upstream has

  • commited https://core.trac.wordpress.org/changeset/32385 though which

  • will enericons example.html files if present. As the file was included

  • in other popular themes and plugins maybe it should as well be included

  • in an update for wordpress for wheezy?

EPSS

Процентиль: 80%
0.01531
Низкий

Связанные уязвимости

ubuntu
около 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

nvd
около 10 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

EPSS

Процентиль: 80%
0.01531
Низкий