Show filters
33 Total Results
Displaying 21-30 of 33
Sort by:
Attacker Value
Unknown

CVE-2012-2404

Disclosure Date: April 21, 2012 (last updated October 04, 2023)
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-2403

Disclosure Date: April 21, 2012 (last updated October 04, 2023)
wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-2401

Disclosure Date: April 21, 2012 (last updated October 04, 2023)
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.
0
Attacker Value
Unknown

CVE-2012-2400

Disclosure Date: April 21, 2012 (last updated October 04, 2023)
Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2012-2402

Disclosure Date: April 21, 2012 (last updated October 04, 2023)
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-2399

Disclosure Date: April 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.
0
Attacker Value
Unknown

CVE-2009-2334

Disclosure Date: July 10, 2009 (last updated October 04, 2023)
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.
0
Attacker Value
Unknown

CVE-2009-2432

Disclosure Date: July 10, 2009 (last updated October 04, 2023)
WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown

CVE-2008-5278

Disclosure Date: November 28, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
0
Attacker Value
Unknown

CVE-2008-4769

Disclosure Date: October 28, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information.
0