CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
32263 | CVE-2008-2146 | Candidate | wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages. | Assigned (20080512) | None (candidate not yet proposed) | View | |
13315 | CVE-2005-2109 | Candidate | wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use. | Assigned (20050701) | None (candidate not yet proposed) | View | |
23466 | CVE-2007-0109 | Candidate | wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks. | Assigned (20070108) | None (candidate not yet proposed) | View | |
40197 | CVE-2009-2762 | Candidate | wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array. | Assigned (20090813) | None (candidate not yet proposed) | View | |
24956 | CVE-2007-1599 | Candidate | wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter. | Assigned (20070322) | None (candidate not yet proposed) | View |
Page 20811 of 20943, showing 5 records out of 104715 total, starting on record 104051, ending on 104055