Vulnerabilities > CVE-2007-0540 - Unspecified vulnerability in Wordpress
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.
Vulnerable Configurations
Exploit-Db
description | WordPress 1.x/2.0.x Pingback SourceURI Denial Of Service and Information Disclosure Vulnerability. CVE-2007-0540. Webapps exploit for php platform |
id | EDB-ID:29522 |
last seen | 2016-02-03 |
modified | 2007-01-24 |
published | 2007-01-24 |
reporter | Blake Matheny |
source | https://www.exploit-db.com/download/29522/ |
title | WordPress 1.x/2.0.x - Pingback SourceURI Denial of Service and Information Disclosure Vulnerability |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1564.NASL |
description | Several remote vulnerabilities have been discovered in WordPress, a weblog manager. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2007-3639 Insufficient input sanitising allowed for remote attackers to redirect visitors to external websites. - CVE-2007-4153 Multiple cross-site scripting vulnerabilities allowed remote authenticated administrators to inject arbitrary web script or HTML. - CVE-2007-4154 SQL injection vulnerability allowed allowed remote authenticated administrators to execute arbitrary SQL commands. - CVE-2007-0540 WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data. - [no CVE name yet] Insufficient input sanitising caused an attacker with a normal user account to access the administrative interface. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 32126 |
published | 2008-05-02 |
reporter | This script is Copyright (C) 2008-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/32126 |
title | Debian DSA-1564-1 : wordpress - multiple vulnerabilities |
code |
|