Vulnerability   
Search   
    Search 187964 CVE descriptions
and 85075 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.704677
Category:Debian Local Security Checks
Title:Debian: Security Advisory for wordpress (DSA-4677-1)
Summary:The remote host is missing an update for the 'wordpress'; package(s) announced via the DSA-4677-1 advisory.
Description:Summary:
The remote host is missing an update for the 'wordpress'
package(s) announced via the DSA-4677-1 advisory.

Vulnerability Insight:
Several vulnerabilities were discovered in Wordpress, a web blogging
tool. They allowed remote attackers to perform various Cross-Side
Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks, create
files on the server, disclose private information, create open
redirects, poison cache, and bypass authorization access and input
sanitation.

Affected Software/OS:
'wordpress' package(s) on Debian Linux.

Solution:
For the oldstable distribution (stretch), these problems have been fixed
in version 4.7.5+dfsg-2+deb9u6.

For the stable distribution (buster), these problems have been fixed in
version 5.0.4+dfsg1-1+deb10u2.

We recommend that you upgrade your wordpress packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-9787
BugTraq ID: 107411
http://www.securityfocus.com/bid/107411
Debian Security Information: DSA-4677 (Google Search)
https://www.debian.org/security/2020/dsa-4677
https://blog.ripstech.com/2019/wordpress-csrf-to-rce/
https://github.com/WordPress/WordPress/commit/0292de60ec78c5a44956765189403654fe4d080b
https://wordpress.org/news/2019/03/wordpress-5-1-1-security-and-maintenance-release/
https://wordpress.org/support/wordpress-version/version-5-1-1/
https://wpvulndb.com/vulnerabilities/9230
https://lists.debian.org/debian-lts-announce/2019/03/msg00044.html
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 85075 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.