Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-1000600

Опубликовано: 06 сент. 2018
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 6.5
CVSS3: 8.8

Описание

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9

РелизСтатусПримечание
bionic

not-affected

4.9.5+dfsg1-1
cosmic

not-affected

4.9.5+dfsg1-1
devel

not-affected

4.9.5+dfsg1-1
disco

not-affected

4.9.5+dfsg1-1
eoan

not-affected

4.9.5+dfsg1-1
esm-apps/bionic

not-affected

4.9.5+dfsg1-1
esm-apps/focal

not-affected

4.9.5+dfsg1-1
esm-apps/jammy

not-affected

4.9.5+dfsg1-1
esm-apps/noble

not-affected

4.9.5+dfsg1-1
esm-apps/xenial

needed

Показывать по

EPSS

Процентиль: 95%
0.18198
Средний

6.5 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
почти 7 лет назад

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9

CVSS3: 8.8
debian
почти 7 лет назад

WordPress version <4.9 contains a CWE-20 Input Validation vulnerabilit ...

CVSS3: 8.8
github
около 3 лет назад

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9

EPSS

Процентиль: 95%
0.18198
Средний

6.5 Medium

CVSS2

8.8 High

CVSS3