CVE List

Id CVE No. Status Description Phase Votes Comments Actions
35230  CVE-2008-5113  Candidate  WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.  Assigned (20081117)  None (candidate not yet proposed)    View
30308  CVE-2008-0191  Candidate  WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.  Assigned (20080109)  None (candidate not yet proposed)    View
24634  CVE-2007-1277  Candidate  WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.  Assigned (20070305)  None (candidate not yet proposed)    View
23619  CVE-2007-0262  Candidate  WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.  Assigned (20070116)  None (candidate not yet proposed)    View
19494  CVE-2006-3390  Candidate  WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.  Assigned (20060706)  None (candidate not yet proposed)    View

Page 150 of 20943, showing 5 records out of 104715 total, starting on record 746, ending on 750

Actions