Количество 1 894
Количество 1 894
CVE-2012-6634
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote atta ...

CVE-2012-6633
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

CVE-2012-6633
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.
CVE-2012-6633
Cross-site scripting (XSS) vulnerability in wp-includes/default-filter ...

CVE-2012-5868
WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVE-2012-5868
WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.
CVE-2012-5868
WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upo ...

CVE-2012-4448
Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

CVE-2012-4448
Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.
CVE-2012-4448
Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php ...

CVE-2012-4422
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

CVE-2012-4422
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.
CVE-2012-4422
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite fea ...

CVE-2012-4421
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

CVE-2012-4421
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.
CVE-2012-4421
The create_post function in wp-includes/class-wp-atom-server.php in Wo ...

CVE-2012-3385
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

CVE-2012-3385
WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.
CVE-2012-3385
WordPress before 3.4.1 does not properly restrict access to post conte ...

CVE-2012-3384
Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
CVE-2012-6634 wp-admin/media-upload.php in WordPress before 3.3.3 allows remote atta ... | CVSS2: 6.4 | 1% Низкий | больше 11 лет назад | |
![]() | CVE-2012-6633 Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field. | CVSS2: 4.3 | 0% Низкий | больше 11 лет назад |
![]() | CVE-2012-6633 Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field. | CVSS2: 4.3 | 0% Низкий | больше 11 лет назад |
CVE-2012-6633 Cross-site scripting (XSS) vulnerability in wp-includes/default-filter ... | CVSS2: 4.3 | 0% Низкий | больше 11 лет назад | |
![]() | CVE-2012-5868 WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack. | CVSS2: 2.6 | 1% Низкий | больше 12 лет назад |
![]() | CVE-2012-5868 WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack. | CVSS2: 2.6 | 1% Низкий | больше 12 лет назад |
CVE-2012-5868 WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upo ... | CVSS2: 2.6 | 1% Низкий | больше 12 лет назад | |
![]() | CVE-2012-4448 Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action. | CVSS2: 6.8 | 0% Низкий | почти 13 лет назад |
![]() | CVE-2012-4448 Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action. | CVSS2: 6.8 | 0% Низкий | почти 13 лет назад |
CVE-2012-4448 Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php ... | CVSS2: 6.8 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-4422 wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role. | CVSS2: 3.5 | 0% Низкий | почти 13 лет назад |
![]() | CVE-2012-4422 wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role. | CVSS2: 3.5 | 0% Низкий | почти 13 лет назад |
CVE-2012-4422 wp-admin/plugins.php in WordPress before 3.4.2, when the multisite fea ... | CVSS2: 3.5 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-4421 The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature. | CVSS2: 4 | 0% Низкий | почти 13 лет назад |
![]() | CVE-2012-4421 The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature. | CVSS2: 4 | 0% Низкий | почти 13 лет назад |
CVE-2012-4421 The create_post function in wp-includes/class-wp-atom-server.php in Wo ... | CVSS2: 4 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-3385 WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors. | CVSS2: 5 | 1% Низкий | около 13 лет назад |
![]() | CVE-2012-3385 WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors. | CVSS2: 5 | 1% Низкий | около 13 лет назад |
CVE-2012-3385 WordPress before 3.4.1 does not properly restrict access to post conte ... | CVSS2: 5 | 1% Низкий | около 13 лет назад | |
![]() | CVE-2012-3384 Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | CVSS2: 6.8 | 0% Низкий | около 13 лет назад |
Уязвимостей на страницу