4.3

CVE-2007-1049

Exploit

WordPress Core < 2.09 - Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.
Mögliche Gegenmaßnahme
WordPress: Update to one of the following versions, or a newer patched version: 2.0.9, 2.1.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wordpress ≫ Wordpress Version 0.6.2 Update beta_2
Wordpress ≫ Wordpress Version 0.6.2.1 Update beta_2
Wordpress ≫ Wordpress Version 0.7
Wordpress ≫ Wordpress Version 0.71
Wordpress ≫ Wordpress Version 1.2.2
Wordpress ≫ Wordpress Version 1.5
Wordpress ≫ Wordpress Version 1.5.1
Wordpress ≫ Wordpress Version 1.5.1.2
Wordpress ≫ Wordpress Version 1.5.1.3
Wordpress ≫ Wordpress Version 1.5.2
Wordpress ≫ Wordpress Version 2.0
Wordpress ≫ Wordpress Version 2.0.1
Wordpress ≫ Wordpress Version 2.0.2
Wordpress ≫ Wordpress Version 2.0.3
Wordpress ≫ Wordpress Version 2.0.4
Wordpress ≫ Wordpress Version 2.0.5
Wordpress ≫ Wordpress Version 2.0.6
Wordpress ≫ Wordpress Version 2.0.7
Wordpress ≫ Wordpress Version 1.2
   Gentoo ≫ Linux
   Gentoo ≫ Linux Version 1.4
Wordpress ≫ Wordpress Version 1.2.1
   Gentoo ≫ Linux
Weitere Schwachstelleninformationen
SystemWordPress Core
≫
Produkt WordPress
Version [*, 2.0.9)
Version 2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.27% 0.928
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://downloads.securityfocus.com/vulnerabilities/exploits/22534.html
Exploit
http://osvdb.org/33766
http://secunia.com/advisories/24306
http://secunia.com/advisories/24566
http://trac.wordpress.org/changeset/4876
Patch
http://trac.wordpress.org/changeset/4877
http://trac.wordpress.org/ticket/3781
Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml
http://www.securityfocus.com/bid/22534
http://www.vupen.com/english/advisories/2007/0741
https://www.wordfence.com/threat-intel/vulnerabilities/id/b16d675f-1b62-4e3e-b91b-7bdb1e70a221
Third Party Advisory