Description
Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.
Remediation
References
Related Vulnerabilities
CakePHP Improper Input Validation Vulnerability (CVE-2010-4335)
WordPress Plugin wp superb Slideshow Information Disclosure (2.4)
Joomla Other Vulnerability (CVE-2006-1956)
Joomla! Core Denial of Service (2.5.0 - 3.9.27)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1167)