|
247841
|
7.5 |
HIGH
Network
|
wordpress
|
wordpress
|
wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended a…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2017-5493
|
2024-11-21 12:27 |
2017-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247842
|
8.8 |
HIGH
Network
|
wordpress
|
wordpress
|
Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims …
|
CWE-352
Origin Validation Error
|
CVE-2017-5492
|
2024-11-21 12:27 |
2017-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247843
|
5.3 |
MEDIUM
Network
|
wordpress
|
wordpress
|
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2017-5491
|
2024-11-21 12:27 |
2017-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247844
|
6.1 |
MEDIUM
Network
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5490
|
2024-11-21 12:27 |
2017-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247845
|
8.8 |
HIGH
Network
|
wordpress
|
wordpress
|
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.
|
CWE-352
Origin Validation Error
|
CVE-2017-5489
|
2024-11-21 12:27 |
2017-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247846
|
6.1 |
MEDIUM
Network
|
wordpress
|
wordpress
|
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5488
|
2024-11-21 12:27 |
2017-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247847
|
5.3 |
MEDIUM
Network
|
wordpress
|
wordpress
|
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote…
|
CWE-200
Information Exposure
|
CVE-2017-5487
|
2024-11-21 12:27 |
2017-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247848
|
8.8 |
HIGH
Network
|
s9y
|
serendipity
|
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
|
CWE-352
Origin Validation Error
|
CVE-2017-5476
|
2024-11-21 12:27 |
2017-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247849
|
8.8 |
HIGH
Network
|
s9y
|
serendipity
|
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
|
CWE-352
Origin Validation Error
|
CVE-2017-5475
|
2024-11-21 12:27 |
2017-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247850
|
6.1 |
MEDIUM
Network
|
s9y
|
serendipity
|
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer hea…
|
CWE-601
Open Redirect
|
CVE-2017-5474
|
2024-11-21 12:27 |
2017-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|