mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 02:42:13 +02:00
18 lines
774 B
Markdown
18 lines
774 B
Markdown
### [CVE-2014-4537](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4537)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Cross-site scripting (XSS) vulnerability in inpage.tpl.php in the Keyword Strategy Internal Links plugin 2.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) sort, (2) search, or (3) dir parameter.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://codevigilant.com/disclosure/wp-plugin-keyword-strategy-internal-links-a3-cross-site-scripting-xss
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|