Show filters
472 Total Results
Displaying 191-200 of 472
Sort by:
Attacker Value
Unknown
CVE-2017-5491
Disclosure Date: January 15, 2017 (last updated November 25, 2024)
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
0
Attacker Value
Unknown
CVE-2016-7169
Disclosure Date: January 05, 2017 (last updated November 25, 2024)
Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.
0
Attacker Value
Unknown
CVE-2016-7168
Disclosure Date: January 05, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
0
Attacker Value
Unknown
CVE-2016-10033
Disclosure Date: December 30, 2016 (last updated February 15, 2024)
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
0
Attacker Value
Unknown
CVE-2016-10045
Disclosure Date: December 30, 2016 (last updated November 25, 2024)
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.
0
Attacker Value
Unknown
CVE-2016-6635
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.
0
Attacker Value
Unknown
CVE-2016-4029
Disclosure Date: August 07, 2016 (last updated February 09, 2024)
WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
0
Attacker Value
Unknown
CVE-2016-6634
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-5835
Disclosure Date: June 29, 2016 (last updated November 25, 2024)
WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.
0
Attacker Value
Unknown
CVE-2016-5833
Disclosure Date: June 29, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.
0