CVE List

Id CVE No. Status Description Phase Votes Comments Actions
32263  CVE-2008-2146  Candidate  wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.  Assigned (20080512)  None (candidate not yet proposed)    View
13315  CVE-2005-2109  Candidate  wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.  Assigned (20050701)  None (candidate not yet proposed)    View
23466  CVE-2007-0109  Candidate  wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.  Assigned (20070108)  None (candidate not yet proposed)    View
40197  CVE-2009-2762  Candidate  wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.  Assigned (20090813)  None (candidate not yet proposed)    View
24956  CVE-2007-1599  Candidate  wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter.  Assigned (20070322)  None (candidate not yet proposed)    View

Page 20811 of 20943, showing 5 records out of 104715 total, starting on record 104051, ending on 104055

Actions