RULE(RULE ID:310773)

Rule General Information
Release Date: 2014-03-31
Rule Name: Wordpress Platinum SEO Pack 's' Parameter Cross Site Scripting Vulnerability (CVE-2013-5918)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Other Unix, Linux
Reference: http://www.osvdb.org/97263
http://osvdb.org/ref/97/platinum_seo.txt
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.osvdb.org/97263