Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.66.76.86.97.07.12024202520262027

Недавние уязвимости WordPress

Количество 1 914

debian логотип

CVE-2007-1277

больше 19 лет назад

WordPress 2.1.1, as downloaded from some official distribution sites d ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2007-1277

больше 19 лет назад

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2007-1277

больше 19 лет назад

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2007-1244

больше 19 лет назад

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in W ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1244

больше 19 лет назад

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-1244

больше 19 лет назад

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-1230

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/fun ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1230

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2007-1230

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2007-1049

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce funct ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2007-1277

WordPress 2.1.1, as downloaded from some official distribution sites d ...

CVSS2: 7.5
27%
Средний
больше 19 лет назад
ubuntu логотип
CVE-2007-1277

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.

CVSS2: 7.5
27%
Средний
больше 19 лет назад
nvd логотип
CVE-2007-1277

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.

CVSS2: 7.5
27%
Средний
больше 19 лет назад
debian логотип
CVE-2007-1244

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in W ...

CVSS2: 6.8
7%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1244

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
7%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1244

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
7%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/fun ...

CVSS2: 5.8
2%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
2%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1049

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce funct ...

CVSS2: 4.3
6%
Низкий
больше 19 лет назад

Уязвимостей на страницу


Поделиться