Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

nvd логотип

CVE-2007-3639

около 19 лет назад

WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2007-3639

около 19 лет назад

WordPress before 2.2.2 allows remote attackers to redirect visitors to ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2007-3241

около 19 лет назад

Cross-site scripting (XSS) vulnerability in blogroll.php in the cordobo-green-park theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3240

около 19 лет назад

Cross-site scripting (XSS) vulnerability in 404.php in the Vistered-Little theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI) that accesses index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3239

около 19 лет назад

Cross-site scripting (XSS) vulnerability in searchform.php in the AndyBlue theme before 20070607 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3238

около 19 лет назад

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2007-3238

около 19 лет назад

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2007-3238

около 19 лет назад

Cross-site scripting (XSS) vulnerability in functions.php in the defau ...

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2007-3140

около 19 лет назад

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2007-3140

около 19 лет назад

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2007-3140

около 19 лет назад

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remo ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2007-2821

около 19 лет назад

SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-2821

около 19 лет назад

SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2007-2821

около 19 лет назад

SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress be ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-2627

около 19 лет назад

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-2627

около 19 лет назад

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-2627

около 19 лет назад

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1897

больше 19 лет назад

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2007-1897

больше 19 лет назад

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2007-1897

больше 19 лет назад

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, ...

CVSS2: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2007-3639

WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.

CVSS2: 4
2%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3639

WordPress before 2.2.2 allows remote attackers to redirect visitors to ...

CVSS2: 4
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3241

Cross-site scripting (XSS) vulnerability in blogroll.php in the cordobo-green-park theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI.

CVSS2: 4.3
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3240

Cross-site scripting (XSS) vulnerability in 404.php in the Vistered-Little theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI) that accesses index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

CVSS2: 4.3
3%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3239

Cross-site scripting (XSS) vulnerability in searchform.php in the AndyBlue theme before 20070607 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

CVSS2: 4.3
3%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-3238

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

CVSS2: 6
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3238

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

CVSS2: 6
2%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3238

Cross-site scripting (XSS) vulnerability in functions.php in the defau ...

CVSS2: 6
2%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-3140

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.

CVSS2: 6.5
7%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3140

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.

CVSS2: 6.5
7%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3140

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remo ...

CVSS2: 6.5
7%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-2821

SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter.

CVSS2: 7.5
5%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-2821

SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter.

CVSS2: 7.5
5%
Низкий
около 19 лет назад
debian логотип
CVE-2007-2821

SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress be ...

CVSS2: 7.5
5%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-2627

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.

CVSS2: 6.8
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-2627

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.

CVSS2: 6.8
2%
Низкий
около 19 лет назад
debian логотип
CVE-2007-2627

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, ...

CVSS2: 6.8
2%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-1897

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.

CVSS2: 6.5
7%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1897

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.

CVSS2: 6.5
7%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1897

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, ...

CVSS2: 6.5
7%
Низкий
больше 19 лет назад

Уязвимостей на страницу