Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

nvd логотип

CVE-2013-0235

больше 12 лет назад

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

CVSS2: 6.4
EPSS: Средний
debian логотип

CVE-2013-0235

больше 12 лет назад

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to se ...

CVSS2: 6.4
EPSS: Средний
ubuntu логотип

CVE-2012-6707

больше 8 лет назад

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-6707

больше 8 лет назад

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2012-6707

больше 8 лет назад

WordPress through 4.8.2 uses a weak MD5-based password hashing algorit ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-6635

около 12 лет назад

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-6635

около 12 лет назад

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-6635

около 12 лет назад

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3. ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-6634

около 12 лет назад

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2012-6634

около 12 лет назад

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2012-6634

около 12 лет назад

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote atta ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-6633

около 12 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-6633

около 12 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-6633

около 12 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/default-filter ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-5868

около 13 лет назад

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-5868

около 13 лет назад

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2012-5868

около 13 лет назад

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upo ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2012-4448

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-4448

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-4448

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php ...

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2013-0235

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

CVSS2: 6.4
65%
Средний
больше 12 лет назад
debian логотип
CVE-2013-0235

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to se ...

CVSS2: 6.4
65%
Средний
больше 12 лет назад
ubuntu логотип
CVE-2012-6707

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2012-6707

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2012-6707

WordPress through 4.8.2 uses a weak MD5-based password hashing algorit ...

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2012-6635

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.

CVSS2: 4
1%
Низкий
около 12 лет назад
nvd логотип
CVE-2012-6635

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.

CVSS2: 4
1%
Низкий
около 12 лет назад
debian логотип
CVE-2012-6635

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3. ...

CVSS2: 4
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2012-6634

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.

CVSS2: 6.4
1%
Низкий
около 12 лет назад
nvd логотип
CVE-2012-6634

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.

CVSS2: 6.4
1%
Низкий
около 12 лет назад
debian логотип
CVE-2012-6634

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote atta ...

CVSS2: 6.4
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2012-6633

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS2: 4.3
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2012-6633

Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVSS2: 4.3
0%
Низкий
около 12 лет назад
debian логотип
CVE-2012-6633

Cross-site scripting (XSS) vulnerability in wp-includes/default-filter ...

CVSS2: 4.3
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2012-5868

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVSS2: 2.6
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2012-5868

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVSS2: 2.6
1%
Низкий
около 13 лет назад
debian логотип
CVE-2012-5868

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upo ...

CVSS2: 2.6
1%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2012-4448

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-4448

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-4448

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php ...

CVSS2: 6.8
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу