{"id":"CVE-2007-1894","details":"Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.","modified":"2026-04-10T03:38:48.574904Z","published":"2007-04-09T20:19:00Z","references":[{"type":"ADVISORY","url":"http://chxsecurity.org/advisories/adv-1-mid.txt"},{"type":"ADVISORY","url":"http://secunia.com/advisories/24485"},{"type":"ADVISORY","url":"http://secunia.com/advisories/25108"},{"type":"ADVISORY","url":"http://www.debian.org/security/2007/dsa-1285"},{"type":"FIX","url":"http://secunia.com/advisories/24485"},{"type":"FIX","url":"http://www.securityfocus.com/bid/22902"},{"type":"WEB","url":"http://securityreason.com/securityalert/2526"},{"type":"WEB","url":"http://trac.wordpress.org/changeset/5003"},{"type":"WEB","url":"http://trac.wordpress.org/ticket/4093"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/462374/100/0/threaded"}],"schema_version":"1.7.5"}