CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23464  CVE-2007-0107  Candidate  WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.  Assigned (20070108)  None (candidate not yet proposed)    View
22121  CVE-2006-6017  Candidate  WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.  Assigned (20061121)  None (candidate not yet proposed)    View
15667  CVE-2005-4463  Candidate  WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error message related to undefined functions or failed includes. NOTE: the wp-admin/menu-header.php vector is already covered by CVE-2005-2110. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors were also reported to affect WordPress 2.0.1.  Assigned (20051221)  None (candidate not yet proposed)    View
39770  CVE-2009-2335  Candidate  WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."  Assigned (20090705)  None (candidate not yet proposed)    View
39867  CVE-2009-2432  Candidate  WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.  Assigned (20090710)  None (candidate not yet proposed)    View

Page 147 of 20943, showing 5 records out of 104715 total, starting on record 731, ending on 735

Actions