Description
Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.
Remediation
References
Related Vulnerabilities
Internet Information Services Configuration Vulnerability (CVE-1999-0725)
WordPress Plugin Greg's High Performance SEO Cross-Site Scripting (1.6.1)
WordPress Plugin Wholesale Market for WooCommerce Directory Traversal (1.0.8)
WordPress 'blog.header.php' Multiple SQL Injection Vulnerabilities (0.6.2 - 0.71)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5479)