Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.66.76.86.97.07.12024202520262027

Недавние уязвимости WordPress

Количество 1 914

nvd логотип

CVE-2007-0541

больше 19 лет назад

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-0262

больше 19 лет назад

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify t ...

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2007-0262

больше 19 лет назад

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2007-0262

больше 19 лет назад

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2007-0233

больше 19 лет назад

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unse ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2007-0233

больше 19 лет назад

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2007-0233

больше 19 лет назад

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2007-0107

больше 19 лет назад

WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alte ...

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-0106

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the CSRF protection scheme ...

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-0109

больше 19 лет назад

wp-login.php in WordPress 2.0.5 and earlier displays different error m ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
3%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0262

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify t ...

CVSS2: 7.8
3%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-0262

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS2: 7.8
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0262

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS2: 7.8
3%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0233

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unse ...

CVSS2: 7.5
12%
Средний
больше 19 лет назад
ubuntu логотип
CVE-2007-0233

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.

CVSS2: 7.5
12%
Средний
больше 19 лет назад
nvd логотип
CVE-2007-0233

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.

CVSS2: 7.5
12%
Средний
больше 19 лет назад
debian логотип
CVE-2007-0107

WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alte ...

CVSS2: 6.8
8%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0106

Cross-site scripting (XSS) vulnerability in the CSRF protection scheme ...

CVSS2: 6.8
3%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0109

wp-login.php in WordPress 2.0.5 and earlier displays different error m ...

CVSS2: 5
3%
Низкий
больше 19 лет назад

Уязвимостей на страницу


Поделиться