Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

ubuntu логотип

CVE-2019-8943

больше 7 лет назад

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVSS3: 6.5
EPSS: Критический
nvd логотип

CVE-2019-8943

больше 7 лет назад

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVSS3: 6.5
EPSS: Критический
debian логотип

CVE-2019-8943

больше 7 лет назад

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An a ...

CVSS3: 6.5
EPSS: Критический
ubuntu логотип

CVE-2019-8942

больше 7 лет назад

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

CVSS3: 8.8
EPSS: Высокий
nvd логотип

CVE-2019-8942

больше 7 лет назад

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

CVSS3: 8.8
EPSS: Высокий
debian логотип

CVE-2019-8942

больше 7 лет назад

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code executi ...

CVSS3: 8.8
EPSS: Высокий
ubuntu логотип

CVE-2019-20043

больше 6 лет назад

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-20043

больше 6 лет назад

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2019-20043

больше 6 лет назад

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.ph ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2019-20042

больше 6 лет назад

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-20042

больше 6 лет назад

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-20042

больше 6 лет назад

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-20041

больше 6 лет назад

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-20041

больше 6 лет назад

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-20041

больше 6 лет назад

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-17675

почти 7 лет назад

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-17675

почти 7 лет назад

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-17675

почти 7 лет назад

WordPress before 5.2.4 does not properly consider type confusion durin ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-17674

почти 7 лет назад

WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-17674

почти 7 лет назад

WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-8943

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVSS3: 6.5
93%
Критический
больше 7 лет назад
nvd логотип
CVE-2019-8943

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVSS3: 6.5
93%
Критический
больше 7 лет назад
debian логотип
CVE-2019-8943

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An a ...

CVSS3: 6.5
93%
Критический
больше 7 лет назад
ubuntu логотип
CVE-2019-8942

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

CVSS3: 8.8
83%
Высокий
больше 7 лет назад
nvd логотип
CVE-2019-8942

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

CVSS3: 8.8
83%
Высокий
больше 7 лет назад
debian логотип
CVE-2019-8942

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code executi ...

CVSS3: 8.8
83%
Высокий
больше 7 лет назад
ubuntu логотип
CVE-2019-20043

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

CVSS3: 4.3
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-20043

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

CVSS3: 4.3
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-20043

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.ph ...

CVSS3: 4.3
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-20042

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

CVSS3: 6.1
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-20042

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

CVSS3: 6.1
3%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-20042

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function ...

CVSS3: 6.1
3%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-20041

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVSS3: 9.8
5%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-20041

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

CVSS3: 9.8
5%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-20041

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 ...

CVSS3: 9.8
5%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-17675

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

CVSS3: 8.8
3%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-17675

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

CVSS3: 8.8
3%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-17675

WordPress before 5.2.4 does not properly consider type confusion durin ...

CVSS3: 8.8
3%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-17674

WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.

CVSS3: 5.4
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-17674

WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.

CVSS3: 5.4
2%
Низкий
почти 7 лет назад

Уязвимостей на страницу