Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

nvd логотип

CVE-2009-2431

около 17 лет назад

WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-2431

около 17 лет назад

WordPress 2.7.1 places the username of a post's author in an HTML comm ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6767

больше 17 лет назад

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-6767

больше 17 лет назад

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2008-6767

больше 17 лет назад

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attac ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2008-6762

больше 17 лет назад

Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-6762

больше 17 лет назад

Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-6762

больше 17 лет назад

Open redirect vulnerability in wp-admin/upgrade.php in WordPress, prob ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-5278

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2008-5278

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

EPSS: Низкий
nvd логотип

CVE-2008-5278

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-5278

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in the self_link function in ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-5113

больше 17 лет назад

WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2008-5113

больше 17 лет назад

WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.

EPSS: Низкий
nvd логотип

CVE-2008-5113

больше 17 лет назад

WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2008-5113

больше 17 лет назад

WordPress 2.6.3 relies on the REQUEST superglobal array in certain dan ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2008-4769

почти 18 лет назад

Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2008-4769

почти 18 лет назад

Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2008-4769

почти 18 лет назад

Directory traversal vulnerability in the get_category_template functio ...

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2008-4106

почти 18 лет назад

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.

CVSS2: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2009-2431

WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.

CVSS2: 5
3%
Низкий
около 17 лет назад
debian логотип
CVE-2009-2431

WordPress 2.7.1 places the username of a post's author in an HTML comm ...

CVSS2: 5
3%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2008-6767

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

CVSS2: 10
5%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6767

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

CVSS2: 10
5%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-6767

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attac ...

CVSS2: 10
5%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6762

Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.

CVSS2: 4.3
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-6762

Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.

CVSS2: 4.3
2%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-6762

Open redirect vulnerability in wp-admin/upgrade.php in WordPress, prob ...

CVSS2: 4.3
2%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-5278

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

CVSS2: 4.3
3%
Низкий
больше 17 лет назад
redhat логотип
CVE-2008-5278

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-5278

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

CVSS2: 4.3
3%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-5278

Cross-site scripting (XSS) vulnerability in the self_link function in ...

CVSS2: 4.3
3%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-5113

WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.

CVSS2: 4
1%
Низкий
больше 17 лет назад
redhat логотип
CVE-2008-5113

WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.

1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-5113

WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.

CVSS2: 4
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-5113

WordPress 2.6.3 relies on the REQUEST superglobal array in certain dan ...

CVSS2: 4
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-4769

Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
9%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4769

Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
9%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4769

Directory traversal vulnerability in the get_category_template functio ...

CVSS2: 9.3
9%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-4106

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.

CVSS2: 5.1
5%
Низкий
почти 18 лет назад

Уязвимостей на страницу