- EPSS 0.75%
- Veröffentlicht 21.11.2006 23:07:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.
- EPSS 2.82%
- Veröffentlicht 21.11.2006 23:07:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed ...
- EPSS 4.87%
- Veröffentlicht 04.11.2006 01:07:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters i...
- EPSS 0.86%
- Veröffentlicht 13.09.2006 22:07:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup....
- EPSS 5.59%
- Veröffentlicht 09.08.2006 20:04:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely th...
- EPSS 1.2%
- Veröffentlicht 06.07.2006 20:05:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third p...
- EPSS 1.36%
- Veröffentlicht 06.07.2006 20:05:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.
- EPSS 1.44%
- Veröffentlicht 31.05.2006 10:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].
CVE-2006-2667
- EPSS 32.19%
- Veröffentlicht 30.05.2006 21:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence in...
CVE-2006-1796
- EPSS 0.46%
- Veröffentlicht 17.04.2006 20:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explor...