Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

debian логотип

CVE-2007-1277

больше 19 лет назад

WordPress 2.1.1, as downloaded from some official distribution sites d ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2007-1244

больше 19 лет назад

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-1244

больше 19 лет назад

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-1244

больше 19 лет назад

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in W ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1230

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2007-1230

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2007-1230

больше 19 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/fun ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1049

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-1049

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-1049

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce funct ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-0541

больше 19 лет назад

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0541

больше 19 лет назад

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-0541

больше 19 лет назад

WordPress allows remote attackers to determine the existence of arbitr ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-0540

больше 19 лет назад

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0540

больше 19 лет назад

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-0540

больше 19 лет назад

WordPress allows remote attackers to cause a denial of service (bandwi ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-0539

больше 19 лет назад

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2007-0539

больше 19 лет назад

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2007-0539

больше 19 лет назад

The wp_remote_fopen function in WordPress before 2.1 allows remote att ...

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2007-0262

больше 19 лет назад

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS2: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2007-1277

WordPress 2.1.1, as downloaded from some official distribution sites d ...

CVSS2: 7.5
27%
Средний
больше 19 лет назад
ubuntu логотип
CVE-2007-1244

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
7%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1244

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

CVSS2: 6.8
7%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1244

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in W ...

CVSS2: 6.8
7%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

CVSS2: 5.8
2%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1230

Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/fun ...

CVSS2: 5.8
2%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1049

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
6%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1049

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.

CVSS2: 4.3
6%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1049

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce funct ...

CVSS2: 4.3
6%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVSS2: 5
3%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitr ...

CVSS2: 5
3%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-0540

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS2: 5
7%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0540

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS2: 5
7%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0540

WordPress allows remote attackers to cause a denial of service (bandwi ...

CVSS2: 5
7%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-0539

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

CVSS2: 7.8
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0539

The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

CVSS2: 7.8
3%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0539

The wp_remote_fopen function in WordPress before 2.1 allows remote att ...

CVSS2: 7.8
3%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-0262

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

CVSS2: 7.8
2%
Низкий
больше 19 лет назад

Уязвимостей на страницу