CVE-2010-4536
Publication date 3 January 2011
Last updated 24 July 2024
Ubuntu priority
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.
Status
Package | Ubuntu Release | Status |
---|---|---|
wordpress | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Fixed 3.0.1-1ubuntu1.1
|
|
10.04 LTS lucid |
Fixed 2.9.2-1ubuntu1.1
|
|
9.10 karmic | Ignored end of life | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life |