CVE-2007-3288
Cross-site scripting (XSS) vulnerability in the skeltoac stats (Automattic Stats) 1.0 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer field.
Date published : 2007-06-20
http://www.securityfocus.com/bid/24551
http://www.securityfocus.com/archive/1/471734/100/0/threaded