Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-4402
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Register Plus plugin 3.5.1 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) firstname, (2) lastname, (3) website, (4) aim, (5) yahoo, (6) jabber, (7) about, (8) pass1, and (9) pass2 parameters in a register action.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-4402
BugTraq ID: 45057
http://www.securityfocus.com/bid/45057
Bugtraq: 20101125 [Suspected Spam]Vulnerabilities in Register Plus for WordPress (Google Search)
http://www.securityfocus.com/archive/1/514903/100/0/threaded
http://packetstormsecurity.org/files/view/96143/registerplus-xss.txt
http://websecurity.com.ua/4539
http://osvdb.org/69491
http://secunia.com/advisories/42360




© 1998-2025 E-Soft Inc. All rights reserved.