Show filters
63 Total Results
Displaying 61-63 of 63
Sort by:
Attacker Value
Unknown

CVE-2007-3238

Disclosure Date: June 15, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.
0
Attacker Value
Unknown

CVE-2007-3140

Disclosure Date: June 08, 2007 (last updated October 04, 2023)
SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.
0
Attacker Value
Unknown

CVE-2007-1894

Disclosure Date: April 09, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.
0