Vulnerability Name:

CVE-2007-1049 (CCN-32675)

Assigned:2007-02-12
Published:2007-02-12
Updated:2011-03-08
Summary:Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-1049

Source: MISC
Type: Exploit
http://downloads.securityfocus.com/vulnerabilities/exploits/22534.html

Source: OSVDB
Type: UNKNOWN
33766

Source: CCN
Type: SA24306
WordPress templates.php Cross-Site Scripting Vulnerability

Source: SECUNIA
Type: UNKNOWN
24306

Source: CCN
Type: SA24566
Gentoo wordpress Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
24566

Source: CONFIRM
Type: Patch
http://trac.wordpress.org/changeset/4876

Source: CONFIRM
Type: UNKNOWN
http://trac.wordpress.org/changeset/4877

Source: CCN
Type: WordPress trac Ticket #3781
Vulnerability in nonce AYS

Source: CONFIRM
Type: Vendor Advisory
http://trac.wordpress.org/ticket/3781

Source: CCN
Type: WordPress Web site
WordPress > Download

Source: CCN
Type: GLSA-200703-23
WordPress: Multiple vulnerabilities

Source: GENTOO
Type: UNKNOWN
GLSA-200703-23

Source: CCN
Type: OSVDB ID: 33766
WordPress wp-admin/templates.php action Parameter XSS

Source: CCN
Type: OSVDB ID: 34361
WordPress wp-includes/functions.php Multiple Method XSS

Source: BID
Type: UNKNOWN
22534

Source: CCN
Type: BID-22534
Wordpress Templates.PHP Cross-Site Scripting Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2007-0741

Source: XF
Type: UNKNOWN
wordpress-templates-xss(32675)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:wordpress:wordpress:0.6.2:beta_2:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.6.2.1:beta_2:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.7:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.71:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.3:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.5:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.6:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.7:-:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:gentoo:linux:1.4:*:*:*:*:*:*:*
  • AND
  • cpe:/a:wordpress:wordpress:1.2:-:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • AND
  • cpe:/a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    wordpress wordpress 0.6.2 beta_2
    wordpress wordpress 0.6.2.1 beta_2
    wordpress wordpress 0.7
    wordpress wordpress 0.71
    wordpress wordpress 1.2.2
    wordpress wordpress 1.5
    wordpress wordpress 1.5.1
    wordpress wordpress 1.5.1.2
    wordpress wordpress 1.5.1.3
    wordpress wordpress 1.5.2
    wordpress wordpress 2.0
    wordpress wordpress 2.0.1
    wordpress wordpress 2.0.2
    wordpress wordpress 2.0.3
    wordpress wordpress 2.0.4
    wordpress wordpress 2.0.5
    wordpress wordpress 2.0.6
    wordpress wordpress 2.0.7
    gentoo linux *
    gentoo linux 1.4
    wordpress wordpress 1.2
    gentoo linux *
    wordpress wordpress 1.2.1