CVE
- Id
- 47877
- CVE No.
- CVE-2010-5293
- Status
- Candidate
- Description
- wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.
- Phase
- Assigned (20140120)
- Votes
- None (candidate not yet proposed)
- Comments