Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

nvd логотип

CVE-2013-2743

больше 13 лет назад

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2013-2742

больше 13 лет назад

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a restore operation, which makes it easier for remote attackers to obtain access via subsequent requests to this script.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2013-2741

больше 13 лет назад

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2013-2709

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-2707

около 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the Login With Ajax plugin before 3.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-2706

больше 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-2704

около 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the Dropdown Menu Widget plugin 1.9.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-2703

около 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the Facebook Members plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify this plugin's settings.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-2702

около 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the Easy AdSense Lite plugin before 6.10 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-2697

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-2696

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the All in One Webmaster plugin before 8.2.4 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-2640

больше 13 лет назад

ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks via unspecified vectors related to "formData=save" requests, a different version than CVE-2013-0731.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-2501

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-2204

около 13 лет назад

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-2204

около 13 лет назад

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-2204

около 13 лет назад

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1949

больше 13 лет назад

Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Trojan Horse), which allows remote attackers to force the upload of arbitrary files.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2013-1464

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1464

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1464

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in assets/player.swf in the A ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2013-2743

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.

CVSS2: 7.5
3%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-2742

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a restore operation, which makes it easier for remote attackers to obtain access via subsequent requests to this script.

CVSS2: 7.5
2%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-2741

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request.

CVSS2: 7.5
3%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-2709

Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS2: 6.8
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-2707

Cross-site request forgery (CSRF) vulnerability in the Login With Ajax plugin before 3.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.

CVSS2: 6.8
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-2706

Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.

CVSS2: 6.8
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2704

Cross-site request forgery (CSRF) vulnerability in the Dropdown Menu Widget plugin 1.9.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.

CVSS2: 6.8
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-2703

Cross-site request forgery (CSRF) vulnerability in the Facebook Members plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify this plugin's settings.

CVSS2: 6.8
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-2702

Cross-site request forgery (CSRF) vulnerability in the Easy AdSense Lite plugin before 6.10 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.

CVSS2: 6.8
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-2697

Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS2: 6.8
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-2696

Cross-site request forgery (CSRF) vulnerability in the All in One Webmaster plugin before 8.2.4 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVSS2: 6.8
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-2640

ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks via unspecified vectors related to "formData=save" requests, a different version than CVE-2013-0731.

CVSS2: 5
2%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-2501

Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field.

CVSS2: 4.3
5%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2013-2204

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

CVSS2: 4.3
3%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-2204

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct content-spoofing attacks, via a crafted string after a ? (question mark) character.

CVSS2: 4.3
3%
Низкий
около 13 лет назад
debian логотип
CVE-2013-2204

moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media ...

CVSS2: 4.3
3%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1949

Social Media Widget (social-media-widget) plugin 4.0 for WordPress contains an externally introduced modification (Trojan Horse), which allows remote attackers to force the upload of arbitrary files.

CVSS2: 5
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2013-1464

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

CVSS2: 4.3
6%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-1464

Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.

CVSS2: 4.3
6%
Низкий
больше 13 лет назад
debian логотип
CVE-2013-1464

Cross-site scripting (XSS) vulnerability in assets/player.swf in the A ...

CVSS2: 4.3
6%
Низкий
больше 13 лет назад

Уязвимостей на страницу