MidnightBSD

Advisories for ad-minister_project

CVE-2013-6993 MEDIUM

Cross-site scripting (XSS) vulnerability in the Ad-minister plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the key parameter in a delete action to wp-admin/tools.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
ad-minister_project ad-minister 0.4.3
ad-minister_project ad-minister *
ad-minister_project ad-minister 0.5
ad-minister_project ad-minister 0.4.2
ad-minister_project ad-minister 0.5.2
ad-minister_project ad-minister 0.4.1
ad-minister_project ad-minister 0.4.4