Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

nvd логотип

CVE-2006-5705

больше 19 лет назад

Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2006-5705

больше 19 лет назад

Multiple directory traversal vulnerabilities in plugins/wp-db-backup.p ...

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2006-4743

больше 19 лет назад

WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) header.php, (13) hello.php, (14) wp-content/themes/default/index.php, (15) links.php, (16) livejournal.php, (17) mt.php, (18) page.php, (19) rss.php, (20) searchform.php, (21) search.php, (22) sidebar.php, (23) single.php, (24) textpattern.php, (25) upgrade-functions.php, (26) upgrade-schema.php, or (27) wp-db-backup.php, which reveal the path in various error messages. NOTE: another researcher has disputed the details of this report, stating that version 2.0.5 does not exist. NOTE: the admin-footer.php, admin-functions.php, default-filters.php, edit-form-advanced.php, edit-link-form.php, edit-page-form.php, kses.php, locale.php, rss-functions.php, template-loader.php, and...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-4743

больше 19 лет назад

WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) header.php, (13) hello.php, (14) wp-content/themes/default/index.php, (15) links.php, (16) livejournal.php, (17) mt.php, (18) page.php, (19) rss.php, (20) searchform.php, (21) search.php, (22) sidebar.php, (23) single.php, (24) textpattern.php, (25) upgrade-functions.php, (26) upgrade-schema.php, or (27) wp-db-backup.php, which reveal the path in various error messages. NOTE: another researcher has disputed the details of this report, stating that version 2.0.5 does not exist. NOTE: the admin-footer.php, admin-functions.php, default-filters.php, edit-form-advanced.php, edit-link-form.php, edit-page-form.php, kses.php, locale.php, rss-functions.php, template-loader.php, and wp

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-4743

больше 19 лет назад

WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensit ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-4028

больше 19 лет назад

Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an unspecified issue related to "Anyone can register" functionality (user registration for guests).

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2006-4028

больше 19 лет назад

Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an unspecified issue related to "Anyone can register" functionality (user registration for guests).

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2006-4028

больше 19 лет назад

Multiple unspecified vulnerabilities in WordPress before 2.0.4 have un ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2006-3390

больше 19 лет назад

WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-3390

больше 19 лет назад

WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-3390

больше 19 лет назад

WordPress 2.0.3 allows remote attackers to obtain the installation pat ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-3389

больше 19 лет назад

index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-3389

больше 19 лет назад

index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-3389

больше 19 лет назад

index.php in WordPress 2.0.3 allows remote attackers to obtain sensiti ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-2702

больше 19 лет назад

vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-2702

больше 19 лет назад

vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-2667

больше 19 лет назад

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2006-2667

больше 19 лет назад

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2006-2667

больше 19 лет назад

Direct static code injection vulnerability in WordPress 2.0.2 and earl ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2006-1796

почти 20 лет назад

Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']).

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2006-5705

Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.

CVSS2: 6
5%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-5705

Multiple directory traversal vulnerabilities in plugins/wp-db-backup.p ...

CVSS2: 6
5%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-4743

WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) header.php, (13) hello.php, (14) wp-content/themes/default/index.php, (15) links.php, (16) livejournal.php, (17) mt.php, (18) page.php, (19) rss.php, (20) searchform.php, (21) search.php, (22) sidebar.php, (23) single.php, (24) textpattern.php, (25) upgrade-functions.php, (26) upgrade-schema.php, or (27) wp-db-backup.php, which reveal the path in various error messages. NOTE: another researcher has disputed the details of this report, stating that version 2.0.5 does not exist. NOTE: the admin-footer.php, admin-functions.php, default-filters.php, edit-form-advanced.php, edit-link-form.php, edit-page-form.php, kses.php, locale.php, rss-functions.php, template-loader.php, and...

CVSS2: 5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-4743

WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) header.php, (13) hello.php, (14) wp-content/themes/default/index.php, (15) links.php, (16) livejournal.php, (17) mt.php, (18) page.php, (19) rss.php, (20) searchform.php, (21) search.php, (22) sidebar.php, (23) single.php, (24) textpattern.php, (25) upgrade-functions.php, (26) upgrade-schema.php, or (27) wp-db-backup.php, which reveal the path in various error messages. NOTE: another researcher has disputed the details of this report, stating that version 2.0.5 does not exist. NOTE: the admin-footer.php, admin-functions.php, default-filters.php, edit-form-advanced.php, edit-link-form.php, edit-page-form.php, kses.php, locale.php, rss-functions.php, template-loader.php, and wp

CVSS2: 5
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-4743

WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensit ...

CVSS2: 5
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-4028

Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an unspecified issue related to "Anyone can register" functionality (user registration for guests).

CVSS2: 10
6%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-4028

Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an unspecified issue related to "Anyone can register" functionality (user registration for guests).

CVSS2: 10
6%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-4028

Multiple unspecified vulnerabilities in WordPress before 2.0.4 have un ...

CVSS2: 10
6%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-3390

WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.

CVSS2: 5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-3390

WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.

CVSS2: 5
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-3390

WordPress 2.0.3 allows remote attackers to obtain the installation pat ...

CVSS2: 5
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-3389

index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.

CVSS2: 5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-3389

index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.

CVSS2: 5
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-3389

index.php in WordPress 2.0.3 allows remote attackers to obtain sensiti ...

CVSS2: 5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-2702

vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].

CVSS2: 5
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2702

vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows ...

CVSS2: 5
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2667

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

CVSS2: 7.5
32%
Средний
больше 19 лет назад
nvd логотип
CVE-2006-2667

Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

CVSS2: 7.5
32%
Средний
больше 19 лет назад
debian логотип
CVE-2006-2667

Direct static code injection vulnerability in WordPress 2.0.2 and earl ...

CVSS2: 7.5
32%
Средний
больше 19 лет назад
nvd логотип
CVE-2006-1796

Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']).

CVSS2: 6.8
0%
Низкий
почти 20 лет назад

Уязвимостей на страницу