Логотип exploitDog
product: "wordpress"
Консоль
Логотип exploitDog

exploitDog

product: "wordpress"

Количество 1 906

Количество 1 906

nvd логотип

CVE-2010-5106

больше 13 лет назад

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2010-5106

больше 13 лет назад

The XML-RPC remote publishing interface in xmlrpc.php in WordPress bef ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4536

около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4536

около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4536

около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used i ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-4257

около 15 лет назад

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2010-4257

около 15 лет назад

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2010-4257

около 15 лет назад

SQL injection vulnerability in the do_trackbacks function in wp-includ ...

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2010-0682

почти 16 лет назад

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
EPSS: Средний
nvd логотип

CVE-2010-0682

почти 16 лет назад

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
EPSS: Средний
debian логотип

CVE-2010-0682

почти 16 лет назад

WordPress 2.9 before 2.9.2 allows remote authenticated users to read t ...

CVSS2: 4
EPSS: Средний
ubuntu логотип

CVE-2009-3891

около 16 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-3891

около 16 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2009-3891

около 16 лет назад

Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2009-3890

около 16 лет назад

Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.

CVSS2: 6
EPSS: Средний
nvd логотип

CVE-2009-3890

около 16 лет назад

Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.

CVSS2: 6
EPSS: Средний
debian логотип

CVE-2009-3890

около 16 лет назад

Unrestricted file upload vulnerability in the wp_check_filetype functi ...

CVSS2: 6
EPSS: Средний
ubuntu логотип

CVE-2009-3622

больше 16 лет назад

Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2009-3622

больше 16 лет назад

Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2009-3622

больше 16 лет назад

Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-5106

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS2: 6.5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2010-5106

The XML-RPC remote publishing interface in xmlrpc.php in WordPress bef ...

CVSS2: 6.5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2010-4536

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.

CVSS2: 4.3
4%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-4536

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.

CVSS2: 4.3
4%
Низкий
около 15 лет назад
debian логотип
CVE-2010-4536

Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used i ...

CVSS2: 4.3
4%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4257

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

CVSS2: 6
3%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-4257

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

CVSS2: 6
3%
Низкий
около 15 лет назад
debian логотип
CVE-2010-4257

SQL injection vulnerability in the do_trackbacks function in wp-includ ...

CVSS2: 6
3%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-0682

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
25%
Средний
почти 16 лет назад
nvd логотип
CVE-2010-0682

WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

CVSS2: 4
25%
Средний
почти 16 лет назад
debian логотип
CVE-2010-0682

WordPress 2.9 before 2.9.2 allows remote authenticated users to read t ...

CVSS2: 4
25%
Средний
почти 16 лет назад
ubuntu логотип
CVE-2009-3891

Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).

CVSS2: 3.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-3891

Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).

CVSS2: 3.5
1%
Низкий
около 16 лет назад
debian логотип
CVE-2009-3891

Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in ...

CVSS2: 3.5
1%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2009-3890

Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.

CVSS2: 6
10%
Средний
около 16 лет назад
nvd логотип
CVE-2009-3890

Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.

CVSS2: 6
10%
Средний
около 16 лет назад
debian логотип
CVE-2009-3890

Unrestricted file upload vulnerability in the wp_check_filetype functi ...

CVSS2: 6
10%
Средний
около 16 лет назад
ubuntu логотип
CVE-2009-3622

Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.

CVSS2: 4.3
6%
Низкий
больше 16 лет назад
redhat логотип
CVE-2009-3622

Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.

CVSS2: 2.1
6%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3622

Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP.

CVSS2: 4.3
6%
Низкий
больше 16 лет назад

Уязвимостей на страницу