Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 894

Количество 1 894

ubuntu логотип

CVE-2010-5295

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-5295

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-5295

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in Wo ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-5294

больше 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-5294

больше 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-5294

больше 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the request_fil ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-5293

больше 11 лет назад

wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2010-5293

больше 11 лет назад

wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2010-5293

больше 11 лет назад

wp-includes/comment.php in WordPress before 3.0.2 does not properly wh ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2010-5106

почти 13 лет назад

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2010-5106

почти 13 лет назад

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2010-5106

почти 13 лет назад

The XML-RPC remote publishing interface in xmlrpc.php in WordPress bef ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4536

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4536

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4536

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used i ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-4257

больше 14 лет назад

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2010-4257

больше 14 лет назад

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2010-4257

больше 14 лет назад

SQL injection vulnerability in the do_trackbacks function in wp-includ ...

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2010-0682

больше 15 лет назад

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
EPSS: Средний
nvd логотип

CVE-2010-0682

больше 15 лет назад

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2010-5295

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2010-5295

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2010-5295

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in Wo ...

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2010-5294

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2010-5294

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2010-5294

Multiple cross-site scripting (XSS) vulnerabilities in the request_fil ...

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2010-5293

wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2010-5293

wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2010-5293

wp-includes/comment.php in WordPress before 3.0.2 does not properly wh ...

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2010-5106

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS2: 6.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2010-5106

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS2: 6.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2010-5106

The XML-RPC remote publishing interface in xmlrpc.php in WordPress bef ...

CVSS2: 6.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2010-4536

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4536

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4536

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used i ...

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-4257

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

CVSS2: 6
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4257

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

CVSS2: 6
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4257

SQL injection vulnerability in the do_trackbacks function in wp-includ ...

CVSS2: 6
3%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-0682

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
23%
Средний
больше 15 лет назад
nvd логотип
CVE-2010-0682

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
23%
Средний
больше 15 лет назад

Уязвимостей на страницу