Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

debian логотип

CVE-2007-1599

больше 18 лет назад

wp-login.php in WordPress allows remote attackers to redirect authenti ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2007-1409

больше 18 лет назад

WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-1409

больше 18 лет назад

WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-1409

больше 18 лет назад

WordPress allows remote attackers to obtain sensitive information via ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-1277

больше 18 лет назад

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.

CVSS2: 7.5
EPSS: Высокий
nvd логотип

CVE-2007-1277

больше 18 лет назад

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.

CVSS2: 7.5
EPSS: Высокий
debian логотип

CVE-2007-1277

больше 18 лет назад

WordPress 2.1.1, as downloaded from some official distribution sites d ...

CVSS2: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2007-1244

больше 18 лет назад

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-1244

больше 18 лет назад

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-1244

больше 18 лет назад

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in W ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1230

больше 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2007-1230

больше 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2007-1230

больше 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/fun ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1049

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-1049

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-1049

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce funct ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-0541

больше 18 лет назад

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0541

больше 18 лет назад

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-0541

больше 18 лет назад

WordPress allows remote attackers to determine the existence of arbitr ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-0540

больше 18 лет назад

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2007-1599

wp-login.php in WordPress allows remote attackers to redirect authenti ...

CVSS2: 6.5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-1409

WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.

CVSS2: 5
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1409

WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.

CVSS2: 5
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1409

WordPress allows remote attackers to obtain sensitive information via ...

CVSS2: 5
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-1277

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.

CVSS2: 7.5
85%
Высокий
больше 18 лет назад
nvd логотип
CVE-2007-1277

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.

CVSS2: 7.5
85%
Высокий
больше 18 лет назад
debian логотип
CVE-2007-1277

WordPress 2.1.1, as downloaded from some official distribution sites d ...

CVSS2: 7.5
85%
Высокий
больше 18 лет назад
ubuntu логотип
CVE-2007-1244

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
10%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1244

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
10%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1244

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in W ...

CVSS2: 6.8
10%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
1%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/fun ...

CVSS2: 5.8
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-1049

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
6%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1049

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
6%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1049

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce funct ...

CVSS2: 4.3
6%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
1%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitr ...

CVSS2: 5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0540

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS2: 5
5%
Низкий
больше 18 лет назад

Уязвимостей на страницу