Show filters
472 Total Results
Displaying 231-240 of 472
Sort by:
Attacker Value
Unknown

CVE-2014-9034

Disclosure Date: November 25, 2014 (last updated October 05, 2023)
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.
0
Attacker Value
Unknown

CVE-2014-9037

Disclosure Date: November 25, 2014 (last updated October 05, 2023)
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
0
Attacker Value
Unknown

CVE-2014-9038

Disclosure Date: November 25, 2014 (last updated October 05, 2023)
wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.
0
Attacker Value
Unknown

CVE-2014-9039

Disclosure Date: November 25, 2014 (last updated October 05, 2023)
wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.
0
Attacker Value
Unknown

CVE-2014-9036

Disclosure Date: November 25, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.
0
Attacker Value
Unknown

CVE-2014-9035

Disclosure Date: November 25, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-9033

Disclosure Date: November 25, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.
0
Attacker Value
Unknown

CVE-2003-1599

Disclosure Date: October 27, 2014 (last updated October 05, 2023)
PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable.
0
Attacker Value
Unknown

CVE-2014-8363

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
SQL injection vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.
0
Attacker Value
Unknown

CVE-2003-1598

Disclosure Date: October 01, 2014 (last updated October 05, 2023)
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.
0