CVE-2008-5278
published 2008-11-28CVE-2008-5278: Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.23%
86.9th percentile
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.5.1-11 (bookworm) | wordpress 2.5.1-11 (bookworm) |
| wordpress | wordpress | <= 2.6.3 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wordpress-mu: XSS vulnerability in RSS Feed Generator
vendor_redhat·2008-11-25·CVSS 4.3
CVE-2008-5278 [MEDIUM] CWE-79 wordpress-mu: XSS vulnerability in RSS Feed Generator
wordpress-mu: XSS vulnerability in RSS Feed Generator
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
Debian
CVE-2008-5278: wordpress - Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS...
vendor_debian·2008·CVSS 4.3
CVE-2008-5278 [MEDIUM] CVE-2008-5278: wordpress - Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS...
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
Scope: local
bookworm: resolved (fixed in 2.5.1-11)
bullseye: resolved (fixed in 2.5.1-11)
forky: resolved (fixed in 2.5.1-11)
sid: resolved (fixed in 2.5.1-11)
trixie: resolved (fixed in 2.5.1-11)
GHSA
GHSA-ggp3-c542-qp4x: Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed
ghsa_unreviewed·2022-05-17
CVE-2008-5278 [MEDIUM] CWE-79 GHSA-ggp3-c542-qp4x: Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
OSV
CVE-2008-5278: Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed
osv·2008-11-28·CVSS 4.3
CVE-2008-5278 [MEDIUM] CVE-2008-5278: Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
No detection rules found.
No public exploits indexed.
http://osvdb.org/50214http://secunia.com/advisories/32882http://secunia.com/advisories/32966http://securityreason.com/securityalert/4662http://wordpress.org/development/2008/11/wordpress-265/http://www.securityfocus.com/archive/1/498652http://www.securityfocus.com/bid/32476https://exchange.xforce.ibmcloud.com/vulnerabilities/46882https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00000.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-December/msg00176.htmlhttp://osvdb.org/50214http://secunia.com/advisories/32882http://secunia.com/advisories/32966http://securityreason.com/securityalert/4662http://wordpress.org/development/2008/11/wordpress-265/http://www.securityfocus.com/archive/1/498652http://www.securityfocus.com/bid/32476https://exchange.xforce.ibmcloud.com/vulnerabilities/46882https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00000.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-December/msg00176.html
2008-11-28
Published