Vulnerabilities > CVE-2007-3238 - Unspecified vulnerability in Wordpress 2.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN wordpress
nessus
Summary
Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1502.NASL |
description | Several remote vulnerabilities have been discovered in wordpress, a weblog manager. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2007-3238 Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php. - CVE-2007-2821 SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter. - CVE-2008-0193 Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. - CVE-2008-0194 Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. Wordpress is not present in the oldstable distribution (sarge). |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 31146 |
published | 2008-02-25 |
reporter | This script is Copyright (C) 2008-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/31146 |
title | Debian DSA-1502-1 : wordpress - several vulnerabilities |
code |
|
References
- http://blogsecurity.net/wordpress/news/news-100607-1/
- http://blogsecurity.net/wordpress/news/news-100607-1/
- http://codex.wordpress.org/Roles_and_Capabilities
- http://codex.wordpress.org/Roles_and_Capabilities
- http://mybeni.rootzilla.de/mybeNi/2007/wordpress_zeroday_vulnerability_roundhouse_kick_and_why_i_nearly_wrote_the_first_blog_worm/
- http://mybeni.rootzilla.de/mybeNi/2007/wordpress_zeroday_vulnerability_roundhouse_kick_and_why_i_nearly_wrote_the_first_blog_worm/
- http://osvdb.org/37293
- http://osvdb.org/37293
- http://secunia.com/advisories/25541/
- http://secunia.com/advisories/25541/
- http://secunia.com/advisories/29014
- http://secunia.com/advisories/29014
- http://securityreason.com/securityalert/2807
- http://securityreason.com/securityalert/2807
- http://www.debian.org/security/2008/dsa-1502
- http://www.debian.org/security/2008/dsa-1502
- http://www.securityfocus.com/archive/1/470837/100/0/threaded
- http://www.securityfocus.com/archive/1/470837/100/0/threaded
- http://www.securityfocus.com/bid/25161
- http://www.securityfocus.com/bid/25161
- http://www.xssnews.com/
- http://www.xssnews.com/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34785
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34785