Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

ubuntu логотип

CVE-2007-1230

почти 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2007-1230

почти 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2007-1230

почти 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/fun ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1049

почти 19 лет назад

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-1049

почти 19 лет назад

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-1049

почти 19 лет назад

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce funct ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-0541

около 19 лет назад

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0541

около 19 лет назад

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-0541

около 19 лет назад

WordPress allows remote attackers to determine the existence of arbitr ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-0540

около 19 лет назад

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0540

около 19 лет назад

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-0540

около 19 лет назад

WordPress allows remote attackers to cause a denial of service (bandwi ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-0539

около 19 лет назад

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2007-0539

около 19 лет назад

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2007-0539

около 19 лет назад

The wp_remote_fopen function in WordPress before 2.1 allows remote att ...

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2007-0262

около 19 лет назад

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2007-0262

около 19 лет назад

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2007-0262

около 19 лет назад

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify t ...

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2007-0233

около 19 лет назад

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2007-0233

около 19 лет назад

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
1%
Низкий
почти 19 лет назад
nvd логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
1%
Низкий
почти 19 лет назад
debian логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/fun ...

CVSS2: 5.8
1%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-1049

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
6%
Низкий
почти 19 лет назад
nvd логотип
CVE-2007-1049

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
6%
Низкий
почти 19 лет назад
debian логотип
CVE-2007-1049

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce funct ...

CVSS2: 4.3
6%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
1%
Низкий
около 19 лет назад
debian логотип
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitr ...

CVSS2: 5
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-0540

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS2: 5
8%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-0540

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS2: 5
8%
Низкий
около 19 лет назад
debian логотип
CVE-2007-0540

WordPress allows remote attackers to cause a denial of service (bandwi ...

CVSS2: 5
8%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-0539

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

CVSS2: 7.8
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-0539

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

CVSS2: 7.8
1%
Низкий
около 19 лет назад
debian логотип
CVE-2007-0539

The wp_remote_fopen function in WordPress before 2.1 allows remote att ...

CVSS2: 7.8
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-0262

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS2: 7.8
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-0262

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS2: 7.8
1%
Низкий
около 19 лет назад
debian логотип
CVE-2007-0262

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify t ...

CVSS2: 7.8
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-0233

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.

CVSS2: 7.5
11%
Средний
около 19 лет назад
nvd логотип
CVE-2007-0233

wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.

CVSS2: 7.5
11%
Средний
около 19 лет назад

Уязвимостей на страницу