Description
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced Custom Fields PRO Security Bypass (5.12)
Microsoft SQL Server Other Vulnerability (CVE-2002-0643)
WordPress Plugin Pricing Table by Supsystic Multiple Vulnerabilities (1.8.1)
WordPress Plugin Hustle-Pop-Ups, Slide-ins and Email Opt-ins CSV Injection (6.0.7)
WordPress Improper Input Validation Vulnerability (CVE-2017-9065)