Summary
This host is running WordPress with Xili Language plugin and is prone to cross site scripting vulnerability.
Impact
Successful exploitation will allow remote attackers to insert arbitrary HTML and script code, which will be executed in a user's browser session in the context of an affected site.
Impact Level: Application
Solution
Update to Xili Language Plugin version 2.8.5 or later, For updates refer to http://wordpress.org/extend/plugins/xili-language
Insight
The input passed via 'lang' parameter to index.php script is not properly validated.
Affected
WordPress Xili Language Plugin version 2.8.4.3 and prior
References
Severity
Classification
-
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities
- @Mail 'admin.php' Cross-Site Scripting Vulnerabilities
- Apache Struts CookBook/Examples Multiple Cross-Site Scripting Vulnerabilities
- 123 Flash Chat Multiple Security Vulnerabilities
- Adobe ColdFusion Multiple Cross Site Scripting Vulnerabilities
- Apache Tomcat Login Constraints Security Bypass Vulnerability