ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2010-4536”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2010-4536
Published
2011-01-03
CVSS:
-
ShadowTrackr CVSS:
0.0
Summary:
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.