Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

nvd Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2015-9509

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 23 ΠΎΠΊΡ‚. 2019
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

ОписаниС

The Easy Digital Downloads (EDD) Content Restriction extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

УязвимыС ΠΊΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€Π°Ρ†ΠΈΠΈ

ΠšΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€Π°Ρ†ΠΈΡ 1

ΠžΠ΄Π½ΠΎΠ²Ρ€Π΅ΠΌΠ΅Π½Π½ΠΎ

Одно из

cpe:2.3:a:awesomemotive:easy_digital_downloads:*:*:*:*:*:wordpress:*:*
ВСрсия ΠΎΡ‚ 1.8 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 1.8.7 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:a:awesomemotive:easy_digital_downloads:*:*:*:*:*:wordpress:*:*
ВСрсия ΠΎΡ‚ 1.9 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 1.9.10 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:a:awesomemotive:easy_digital_downloads:*:*:*:*:*:wordpress:*:*
ВСрсия ΠΎΡ‚ 2.0 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 2.0.5 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:a:awesomemotive:easy_digital_downloads:*:*:*:*:*:wordpress:*:*
ВСрсия ΠΎΡ‚ 2.1 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 2.1.11 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:a:awesomemotive:easy_digital_downloads:*:*:*:*:*:wordpress:*:*
ВСрсия ΠΎΡ‚ 2.2 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 2.2.9 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:a:awesomemotive:easy_digital_downloads:*:*:*:*:*:wordpress:*:*
ВСрсия ΠΎΡ‚ 2.3 (Π²ΠΊΠ»ΡŽΡ‡Π°Ρ) Π΄ΠΎ 2.3.7 (ΠΈΡΠΊΠ»ΡŽΡ‡Π°Ρ)
cpe:2.3:a:easydigitaldownloads:content_restriction:-:*:*:*:*:easy_digital_downloads:*:*

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 62%
0.00432
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Π”Π΅Ρ„Π΅ΠΊΡ‚Ρ‹

CWE-79

БвязанныС уязвимости

CVSS3: 6.1
github
ΠΏΠΎΡ‡Ρ‚ΠΈ 4 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

The Easy Digital Downloads (EDD) Content Restriction extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 62%
0.00432
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Π”Π΅Ρ„Π΅ΠΊΡ‚Ρ‹

CWE-79
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ CVE-2015-9509