Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

github логотип

GHSA-c49p-mmwq-r586

около 3 лет назад

simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation path in a stack trace.

EPSS: Низкий
github логотип

GHSA-89mv-5c9h-c8f7

около 3 лет назад

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

EPSS: Низкий
github логотип

GHSA-5f37-gxvh-23v6

больше 5 лет назад

Remote code execution in PHPMailer

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-4pc3-96mx-wwc8

больше 5 лет назад

Remote code execution in PHPMailer

CVSS3: 9.8
EPSS: Критический
ubuntu логотип

CVE-2016-10045

больше 8 лет назад

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2016-10045

больше 8 лет назад

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2016-10045

больше 8 лет назад

The isMail transport in PHPMailer before 5.2.20 might allow remote att ...

CVSS3: 9.8
EPSS: Критический
ubuntu логотип

CVE-2016-10033

больше 8 лет назад

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2016-10033

больше 8 лет назад

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

CVSS3: 9.8
EPSS: Критический
debian логотип

CVE-2016-10033

больше 8 лет назад

The mailSend function in the isMail transport in PHPMailer before 5.2. ...

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2012-6313

больше 12 лет назад

simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation path in a stack trace.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-3414

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-3414

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-3414

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-4796

больше 16 лет назад

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2008-4796

больше 16 лет назад

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4796

больше 16 лет назад

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2008-4796

больше 16 лет назад

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 a ...

CVSS2: 10
EPSS: Низкий
fstec логотип

BDU:2023-07191

больше 3 лет назад

Уязвимость класса WP_Query системы управления содержимым сайта WordPress, позволяющая нарушителю раскрыть сохраненные учетные данные

CVSS3: 7.5
EPSS: Критический
fstec логотип

BDU:2021-01763

больше 4 лет назад

Уязвимость системы управления содержимым сайта WordPress, связанная с недостатками используемых мер по защите структур веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-c49p-mmwq-r586

simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation path in a stack trace.

7%
Низкий
около 3 лет назад
github логотип
GHSA-89mv-5c9h-c8f7

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

4%
Низкий
около 3 лет назад
github логотип
GHSA-5f37-gxvh-23v6

Remote code execution in PHPMailer

CVSS3: 9.8
94%
Критический
больше 5 лет назад
github логотип
GHSA-4pc3-96mx-wwc8

Remote code execution in PHPMailer

CVSS3: 9.8
94%
Критический
больше 5 лет назад
ubuntu логотип
CVE-2016-10045

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

CVSS3: 9.8
94%
Критический
больше 8 лет назад
nvd логотип
CVE-2016-10045

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

CVSS3: 9.8
94%
Критический
больше 8 лет назад
debian логотип
CVE-2016-10045

The isMail transport in PHPMailer before 5.2.20 might allow remote att ...

CVSS3: 9.8
94%
Критический
больше 8 лет назад
ubuntu логотип
CVE-2016-10033

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

CVSS3: 9.8
94%
Критический
больше 8 лет назад
nvd логотип
CVE-2016-10033

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

CVSS3: 9.8
94%
Критический
больше 8 лет назад
debian логотип
CVE-2016-10033

The mailSend function in the isMail transport in PHPMailer before 5.2. ...

CVSS3: 9.8
94%
Критический
больше 8 лет назад
nvd логотип
CVE-2012-6313

simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation path in a stack trace.

CVSS2: 5
7%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-3414

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS2: 4.3
4%
Низкий
почти 12 лет назад
nvd логотип
CVE-2012-3414

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS2: 4.3
4%
Низкий
почти 12 лет назад
debian логотип
CVE-2012-3414

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload ...

CVSS2: 4.3
4%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2008-4796

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.

CVSS2: 10
1%
Низкий
больше 16 лет назад
redhat логотип
CVE-2008-4796

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.

CVSS2: 7.5
1%
Низкий
больше 16 лет назад
nvd логотип
CVE-2008-4796

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.

CVSS2: 10
1%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-4796

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 a ...

CVSS2: 10
1%
Низкий
больше 16 лет назад
fstec логотип
BDU:2023-07191

Уязвимость класса WP_Query системы управления содержимым сайта WordPress, позволяющая нарушителю раскрыть сохраненные учетные данные

CVSS3: 7.5
91%
Критический
больше 3 лет назад
fstec логотип
BDU:2021-01763

Уязвимость системы управления содержимым сайта WordPress, связанная с недостатками используемых мер по защите структур веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 6.1
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу