CVE-2014-6445
Published Sep 26, 2014
Last updated 10 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through 1.3.10 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) uE or (2) uC parameter.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "8D4B4ECC-1A03-40DB-8923-E2AFFC4A90D2" }, { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3.1:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "CFC16D64-ADEB-47CA-89EE-3DF1B6865ABF" }, { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3.2:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "0F28C305-7215-4797-9648-8144DE148271" }, { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3.3:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "62DB679F-8FE6-4808-AD70-54919C9CFA31" }, { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3.4:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "DA25E8A0-6039-4C6F-A57E-985462156714" }, { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3.5:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "B92BA806-A347-4405-BC26-7613ACB51B39" }, { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3.6:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "9FEA6ED6-0F6A-4FE7-8B01-D47FEE0AC75E" }, { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3.7:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "F0575D3F-5E73-48A8-A190-2187A862EC30" }, { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3.8:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "BF5C3CC5-D4C0-4DB9-972F-324BA188E93B" }, { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3.9:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "D8AD1117-5DA4-4190-9B1A-981702607892" }, { "criteria": "cpe:2.3:a:contactus:contact_form_7_integrations:1.3.10:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "72EEA488-10F5-43F1-AC8E-FDC79F406E38" } ], "operator": "OR" } ] } ]