Search CVE reports


Toggle filters

321 – 330 of 371 results


CVE-2007-3639

Medium priority
Ignored

WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress — — — — —
Show less packages

CVE-2007-3544

Medium priority
Ignored

Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors,...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress — — — — —
Show less packages

CVE-2007-3543

Medium priority
Ignored

Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress — — — — —
Show less packages

CVE-2007-3238

Medium priority
Not affected

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI)...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress — — — — —
Show less packages

CVE-2007-3215

Medium priority

Some fixes available 25 of 38

PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.

8 affected packages

flyspray, glpi, ipplan, knowledgeroot, libphp-phpmailer...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flyspray — — — — —
glpi — — — — —
ipplan — — — — —
knowledgeroot — — — — —
libphp-phpmailer — — — — —
moodle — — — — —
owl-dms — — — — —
wordpress — — — — —
Show all 8 packages Show less packages

CVE-2007-3140

Medium priority
Ignored

SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress — — — — —
Show less packages

CVE-2007-2821

Medium priority
Ignored

SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter.

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress — — — — —
Show less packages

CVE-2007-2627

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF),...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress — — — — —
Show less packages

CVE-2007-1897

Medium priority
Ignored

SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories...

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress — — — — —
Show less packages

CVE-2007-1894

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.

1 affected package

wordpress

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wordpress — — — — —
Show less packages