CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
59878 | CVE-2012-6635 | Candidate | wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft. | Assigned (20140120) | None (candidate not yet proposed) | View | |
48613 | CVE-2011-0701 | Candidate | wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter. | Assigned (20110131) | None (candidate not yet proposed) | View | |
39769 | CVE-2009-2334 | Candidate | wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service. | Assigned (20090705) | None (candidate not yet proposed) | View | |
28250 | CVE-2007-4893 | Candidate | wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field. | Assigned (20070914) | None (candidate not yet proposed) | View | |
51731 | CVE-2011-3819 | Candidate | WoW Server Status 4.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by status.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View |
Page 139 of 20943, showing 5 records out of 104715 total, starting on record 691, ending on 695