Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail address, which is not quoted when a parsing error is generated.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/18685 | vdb entry |
http://www.securityfocus.com/bid/12097 | patch vdb entry exploit |
http://marc.info/?l=bugtraq&m=110384387332443&w=2 | mailing list |