Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 912

Количество 1 912

nvd логотип

CVE-2011-1762

больше 4 лет назад

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2011-1762

больше 4 лет назад

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'sc ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-0701

больше 15 лет назад

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2011-0701

больше 15 лет назад

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2011-0701

больше 15 лет назад

wp-admin/async-upload.php in the media uploader in WordPress before 3. ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-0700

больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2011-0700

больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2011-0700

больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2010-5297

больше 12 лет назад

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2010-5297

больше 12 лет назад

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2010-5297

больше 12 лет назад

WordPress before 3.0.1, when a Multisite installation is used, permane ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2010-5296

больше 12 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2010-5296

больше 12 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
EPSS: Низкий
debian логотип

CVE-2010-5296

больше 12 лет назад

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ...

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2010-5295

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-5295

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-5295

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in Wo ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-5294

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-5294

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-5294

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the request_fil ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-1762

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2011-1762

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'sc ...

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2011-0701

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

CVSS2: 4
3%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-0701

wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

CVSS2: 4
3%
Низкий
больше 15 лет назад
debian логотип
CVE-2011-0701

wp-admin/async-upload.php in the media uploader in WordPress before 3. ...

CVSS2: 4
3%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2011-0700

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.

CVSS2: 3.5
3%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-0700

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.

CVSS2: 3.5
3%
Низкий
больше 15 лет назад
debian логотип
CVE-2011-0700

Multiple cross-site scripting (XSS) vulnerabilities in WordPress befor ...

CVSS2: 3.5
3%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2010-5297

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

CVSS2: 2.1
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2010-5297

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

CVSS2: 2.1
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2010-5297

WordPress before 3.0.1, when a Multisite installation is used, permane ...

CVSS2: 2.1
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2010-5296

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2010-5296

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

CVSS2: 4.9
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2010-5296

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ...

CVSS2: 4.9
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2010-5295

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2010-5295

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2010-5295

Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in Wo ...

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2010-5294

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2010-5294

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2010-5294

Multiple cross-site scripting (XSS) vulnerabilities in the request_fil ...

CVSS2: 4.3
1%
Низкий
больше 12 лет назад

Уязвимостей на страницу