CVE-2014-4565
Beschrijving NL
Meerdere cross-site scripting (XSS) -kwetsbaarheden in vcc.js.php in de plug-in Verificatiecode voor opmerkingen 2.1.0 en eerder voor WordPress stellen externe aanvallers in staat om willekeurig webscript of HTML te injecteren via de parameter (1) vp, (2) vs, (3) l, (4) vu of (5) vm.
Origineel (Engels) tonen
Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm parameter.