Описание
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2007-1893
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33470
- http://secunia.com/advisories/24751
- http://secunia.com/advisories/25108
- http://trac.wordpress.org/ticket/4091
- http://www.debian.org/security/2007/dsa-1285
- http://www.notsosecure.com/folder2/2007/04/03/wordpress-212-xmlrpc-security-issues
- http://www.vupen.com/english/advisories/2007/1245
EPSS
CVE ID
Связанные уязвимости
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows r ...
EPSS