Candidate: CVE-2008-4671 PublicDate: 2008-10-22 10:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4671 Description: Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_wordpress: upstream_wordpress: needs-triage dapper_wordpress: not-affected (Debian wordpress installs not vulnerable) gutsy_wordpress: not-affected (Debian wordpress installs not vulnerable) hardy_wordpress: not-affected (Debian wordpress installs not vulnerable) devel_wordpress: not-affected (Debian wordpress installs not vulnerable)