Show filters
50 Total Results
Displaying 41-50 of 50
Sort by:
Attacker Value
Unknown

CVE-2008-5278

Disclosure Date: November 28, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).
0
Attacker Value
Unknown

CVE-2008-4769

Disclosure Date: October 28, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-3747

Disclosure Date: August 27, 2008 (last updated October 04, 2023)
The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.
0
Attacker Value
Unknown

CVE-2008-3233

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-1304

Disclosure Date: March 12, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.
0
Attacker Value
Unknown

CVE-2008-0664

Disclosure Date: February 08, 2008 (last updated October 04, 2023)
The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-0191

Disclosure Date: January 10, 2008 (last updated October 04, 2023)
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.
0
Attacker Value
Unknown

CVE-2008-0193

Disclosure Date: January 10, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.
0
Attacker Value
Unknown

CVE-2007-6318

Disclosure Date: December 12, 2007 (last updated October 04, 2023)
SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a multibyte character.
0
Attacker Value
Unknown

CVE-2007-5710

Disclosure Date: October 30, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.
0