WordPress — свободно распространяемая система управления содержимым сайта с открытым исходным кодом.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 894
CVE-2007-1049
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce funct ...

CVE-2007-1049
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVE-2007-0540
WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVE-2007-0539
The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

CVE-2007-0541
WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.
CVE-2007-0539
The wp_remote_fopen function in WordPress before 2.1 allows remote att ...
CVE-2007-0541
WordPress allows remote attackers to determine the existence of arbitr ...
CVE-2007-0540
WordPress allows remote attackers to cause a denial of service (bandwi ...

CVE-2007-0541
WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVE-2007-0540
WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
CVE-2007-1049 Cross-site scripting (XSS) vulnerability in the wp_explain_nonce funct ... | CVSS2: 4.3 | 6% Низкий | больше 18 лет назад | |
![]() | CVE-2007-1049 Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable. | CVSS2: 4.3 | 6% Низкий | больше 18 лет назад |
![]() | CVE-2007-0540 WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data. | CVSS2: 5 | 5% Низкий | больше 18 лет назад |
![]() | CVE-2007-0539 The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint. | CVSS2: 7.8 | 1% Низкий | больше 18 лет назад |
![]() | CVE-2007-0541 WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment. | CVSS2: 5 | 1% Низкий | больше 18 лет назад |
CVE-2007-0539 The wp_remote_fopen function in WordPress before 2.1 allows remote att ... | CVSS2: 7.8 | 1% Низкий | больше 18 лет назад | |
CVE-2007-0541 WordPress allows remote attackers to determine the existence of arbitr ... | CVSS2: 5 | 1% Низкий | больше 18 лет назад | |
CVE-2007-0540 WordPress allows remote attackers to cause a denial of service (bandwi ... | CVSS2: 5 | 5% Низкий | больше 18 лет назад | |
![]() | CVE-2007-0541 WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment. | CVSS2: 5 | 1% Низкий | больше 18 лет назад |
![]() | CVE-2007-0540 WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data. | CVSS2: 5 | 5% Низкий | больше 18 лет назад |
Уязвимостей на страницу