Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

nvd логотип

CVE-2011-4898

больше 13 лет назад

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4898

больше 13 лет назад

wp-admin/setup-config.php in the installation component in WordPress 3 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-3818

почти 14 лет назад

WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-3818

почти 14 лет назад

WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-3130

около 14 лет назад

wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-3130

около 14 лет назад

wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2011-3130

около 14 лет назад

wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-3129

около 14 лет назад

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2011-3129

около 14 лет назад

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2011-3129

около 14 лет назад

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 be ...

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2011-3128

около 14 лет назад

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-3128

около 14 лет назад

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-3128

около 14 лет назад

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached att ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-3127

около 14 лет назад

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2011-3127

около 14 лет назад

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2011-3127

около 14 лет назад

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rend ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-3126

около 14 лет назад

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-3126

около 14 лет назад

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-3126

около 14 лет назад

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attacke ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-3125

около 14 лет назад

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-4898

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective

CVSS2: 5
10%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4898

wp-admin/setup-config.php in the installation component in WordPress 3 ...

CVSS2: 5
10%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-3818

WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.

CVSS2: 5
0%
Низкий
почти 14 лет назад
nvd логотип
CVE-2011-3818

WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.

CVSS2: 5
0%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2011-3130

wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.

CVSS2: 7.5
0%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3130

wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.

CVSS2: 7.5
0%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3130

wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before ...

CVSS2: 7.5
0%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-3129

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.

CVSS2: 9.3
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3129

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.

CVSS2: 9.3
1%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3129

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 be ...

CVSS2: 9.3
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-3128

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.

CVSS2: 5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3128

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.

CVSS2: 5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3128

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached att ...

CVSS2: 5
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-3127

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS2: 5.8
0%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3127

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS2: 5.8
0%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3127

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rend ...

CVSS2: 5.8
0%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-3126

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

CVSS2: 5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3126

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

CVSS2: 5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3126

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attacke ...

CVSS2: 5
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-3125

Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."

CVSS2: 10
1%
Низкий
около 14 лет назад

Уязвимостей на страницу