CVE-2011-5181
medium · 4.3A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information.
4.3
CVSS
10.4%
EPSS (exploit prob.)
96th
EPSS percentile
2012-09-20
Published
AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| clickdesk | clickdesk_live_support-live_chat_plugin | 2.0 |
| wordpress | wordpress | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/77338
- http://wordpress.org/extend/plugins/clickdesk-live-support-chat-plugin/changelog/
- http://www.securityfocus.com/archive/1/520624/100/0/threaded
- http://www.securityfocus.com/bid/50778
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71469
- http://osvdb.org/77338
- http://wordpress.org/extend/plugins/clickdesk-live-support-chat-plugin/changelog/
- http://www.securityfocus.com/archive/1/520624/100/0/threaded
- http://www.securityfocus.com/bid/50778
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71469
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-5181