Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.54000
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: wordpress
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: wordpress

CVE-2005-2107
Multiple cross-site scripting (XSS) vulnerabilities in post.php in
WordPress 1.5.1.2 and earlier allow remote attackers to inject
arbitrary web script or HTML via the (1) p or (2) comment parameter.

CVE-2005-2108
SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and
earlier allows remote attackers to execute arbitrary SQL commands via
input that is not filtered in the HTTP_RAW_POST_DATA variable, which
stores the data in an XML file.

CVE-2005-2109
wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers
to change the content of the forgotten password e-mail message via the
message variable, which is not initialized before use.

CVE-2005-2110
WordPress 1.5.1.2 and earlier allows remote attackers to obtain
sensitive information via (1) a direct request to menu-header.php or a
'1' value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or
(4) wp-rss2.php, which reveal the path in an error message.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2005-2107
Bugtraq: 20050629 WordPress 1.5.1.2 && Earlier Multiple Vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=112006967221438&w=2
http://www.gulftech.org/?node=research&article_id=00085-06282005
http://secunia.com/advisories/15831
Common Vulnerability Exposure (CVE) ID: CVE-2005-2108
Common Vulnerability Exposure (CVE) ID: CVE-2005-2109
Common Vulnerability Exposure (CVE) ID: CVE-2005-2110
Bugtraq: 20060227 WordPress 2.0.1 Multiple Vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/426304/100/0/threaded
http://NeoSecurityTeam.net/advisories/Advisory-17.txt
CopyrightCopyright (C) 2008 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.