Showing posts with label PHP. Show all posts
Showing posts with label PHP. Show all posts

22 August 2011

XSS Vulnerability in Wordpress 3.2.1


Improper sanitized code in Wordpress Core Module(post-template. 
php) Causing Cross site Scripting. This file can be finded in 
directory /wp-includes. Author can simply Update his Post title
to <a><script>alert('1');</script></a> and its will give out 
alert on index page and post page.