Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

WordPress

WordPressсвободно распространяемая система управления содержимым сайта с открытым исходным кодом.

Релизный цикл, информация об уязвимостях

Продукт: WordPress
Вендор: Wordpress

График релизов

6.56.66.76.86.97.02024202520262027

Недавние уязвимости WordPress

Количество 1 912

nvd логотип

CVE-2006-2667

около 20 лет назад

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2006-2667

около 20 лет назад

Direct static code injection vulnerability in WordPress 2.0.2 and earl ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2006-2667

около 20 лет назад

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2006-1796

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']).

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2006-1796

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the paging links functiona ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2006-1263

больше 20 лет назад

Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-1263

больше 20 лет назад

Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in W ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2006-1263

больше 20 лет назад

Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-1012

больше 20 лет назад

SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2006-1012

больше 20 лет назад

SQL injection vulnerability in WordPress 1.5.2, and possibly other ver ...

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2006-2667

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

CVSS2: 7.5
15%
Средний
около 20 лет назад
debian логотип
CVE-2006-2667

Direct static code injection vulnerability in WordPress 2.0.2 and earl ...

CVSS2: 7.5
15%
Средний
около 20 лет назад
ubuntu логотип
CVE-2006-2667

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

CVSS2: 7.5
15%
Средний
около 20 лет назад
nvd логотип
CVE-2006-1796

Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']).

CVSS2: 6.8
2%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1796

Cross-site scripting (XSS) vulnerability in the paging links functiona ...

CVSS2: 6.8
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1263

Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1263

Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in W ...

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1263

Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1012

SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.

CVSS2: 7.5
3%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1012

SQL injection vulnerability in WordPress 1.5.2, and possibly other ver ...

CVSS2: 7.5
3%
Низкий
больше 20 лет назад

Уязвимостей на страницу


Поделиться