vendor:
Wordpress Plugin
by:
NBBN
7.5
CVSS
HIGH
Multiple Remote Vulnerabilities
200
CWE
Product Name: Wordpress Plugin
Affected Version From: 1.7.2000
Affected Version To: 1.7.2000
Patch Exists: NO
Related CWE:
CPE: a:dmsguestbook:wordpress_plugin:1.7.0
Platforms Tested:
2008
WordPress Plugin dmsguestbook 1.7.0 Multiple Remote Vulnerabilities
The plugin allows for file disclosure and cross-site scripting vulnerabilities. The file disclosure vulnerability allows an attacker to view the config data of Wordpress, including the mysql-server username and password. The cross-site scripting vulnerabilities allow an attacker to execute malicious code on the affected site.
Mitigation:
Update to the latest version of the dmsguestbook plugin or remove it if not needed. Ensure that input validation and output encoding is implemented to prevent cross-site scripting vulnerabilities.