Vulnerability Name: | CVE-2011-0700 (CCN-65313) |
Assigned: | 2011-02-07 |
Published: | 2011-02-07 |
Updated: | 2017-11-21 |
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Access Complexity (AC): Authentication (Au): | Impact Metrics: | Confidentiality (C): Integrity (I): Availibility (A): | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Access Complexity (AC): Athentication (Au):
| Impact Metrics: | Confidentiality (C): Integrity (I): Availibility (A): |
|
Vulnerability Type: | CWE-79
|
Vulnerability Consequences: | Gain Access |
References: | Source: CCN Type: WordPress Web Site Wordpress Version 3.0.5
Source: CONFIRM Type: Patch, Vendor Advisory http://codex.wordpress.org/Version_3.0.5
Source: CONFIRM Type: Patch, Vendor Advisory http://core.trac.wordpress.org/changeset/17397
Source: CONFIRM Type: Patch, Vendor Advisory http://core.trac.wordpress.org/changeset/17401
Source: CONFIRM Type: Patch, Vendor Advisory http://core.trac.wordpress.org/changeset/17406
Source: CONFIRM Type: Patch, Vendor Advisory http://core.trac.wordpress.org/changeset/17412
Source: MITRE Type: CNA CVE-2011-0700
Source: FEDORA Type: Third Party Advisory FEDORA-2011-3408
Source: FEDORA Type: Third Party Advisory FEDORA-2011-3738
Source: FEDORA Type: Third Party Advisory FEDORA-2011-3746
Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20110209 CVE request: wordpress before 3.0.5
Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20110209 Re: CVE request: wordpress before 3.0.5
Source: CCN Type: SA43228 Joomla! CiviCRM Component Multiple Vulnerabilities
Source: SECUNIA Type: Third Party Advisory 43729
Source: DEBIAN Type: Third Party Advisory DSA-2190
Source: DEBIAN Type: DSA-2190 wordpress -- several vulnerabilities
Source: BID Type: Third Party Advisory, VDB Entry 46249
Source: CCN Type: BID-46249 WordPress Prior to 3.0.5 Multiple Security Vulnerabilities
Source: VUPEN Type: Third Party Advisory ADV-2011-0658
Source: VUPEN Type: Third Party Advisory ADV-2011-0721
Source: CONFIRM Type: Patch, Vendor Advisory http://www.wordpress.org/news/2011/02/wordpress-3-0-5/
Source: XF Type: UNKNOWN wordpress-posttitle-xss(65313)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:wordpress:wordpress:*:*:*:*:*:*:*:* (Version <= 3.0.4)
Denotes that component is vulnerable |
Vulnerability Name: | CVE-2011-0700 (CCN-65314) |
Assigned: | 2011-02-07 |
Published: | 2011-02-07 |
Updated: | 2011-02-07 |
Summary: | WordPress is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using tags in the tags meta-box to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. |
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Access Complexity (AC): Authentication (Au): | Impact Metrics: | Confidentiality (C): Integrity (I): Availibility (A): | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Access Complexity (AC): Athentication (Au):
| Impact Metrics: | Confidentiality (C): Integrity (I): Availibility (A): |
|
Vulnerability Consequences: | Gain Access |
References: | Source: CCN Type: WordPress Web Site Wordpress Version 3.0.5
Source: MITRE Type: CNA CVE-2011-0700
Source: CCN Type: SA43238 WordPress Multiple Vulnerabilities
Source: DEBIAN Type: DSA-2190 wordpress -- several vulnerabilities
Source: CCN Type: BID-46249 WordPress Prior to 3.0.5 Multiple Security Vulnerabilities
Source: XF Type: UNKNOWN wordpress-metabox-xss(65314)
|
Vulnerable Configuration: | Configuration CCN 1: cpe:/a:wordpress:wordpress:2.1.1:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1.3:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2.1:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.0.9:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3.2:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3.3:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3.1:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.0.7:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1.3:rc2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1.3:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.5:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.0.8:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6.1:-:*:*:*:*:*:*OR cpe:/a:imagely:nextgen_gallery:2.0.71::~~~wordpress~~:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6.2:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2.0:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1:alpha_3:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3.1:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6.5:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7.1:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3:beta3:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2::revision5003:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2::revision5002:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1.3:rc2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1.3:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6.3:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8.1:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8.2:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8.3:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2::revision5002:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2::revision5003:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8.1:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8.1:beta1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8:beta1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8.1:beta2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8.1:jazzes_themes_and_widgets:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8::iis:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8.2::iis:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.0.7:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.0.7:rc2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.0.8:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.0.9:beta:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.0.9rc1:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1:beta1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1:beta2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1:beta3:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1:beta4:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1:rc2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1.1beta:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1.1:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.1.3:rc3:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.2:rc2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3:beta2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3:beta1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3.1:beta1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3.2:beta:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3.2:beta2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3.2:beta3:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.3.2:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.5:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.5:rc2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.5:rc3:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7:beta1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7:beta2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7:beta3:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6:beta1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6:beta2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6:beta3:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6.1:beta1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.6.1:beta2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7:rc2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7.1:rc1::iis:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7.1:beta1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7.1:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8:beta2:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8:rc1:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.7:coltrane:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8.4:*:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.8.5:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.9:-:*:*:*:*:*:*OR cpe:/a:wordpress:wordpress:2.9.2:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |
wordpress wordpress *
wordpress wordpress 2.1.1 -
wordpress wordpress 2.1.2
wordpress wordpress 2.1.3 -
wordpress wordpress 2.2 -
wordpress wordpress 2.2.1 -
wordpress wordpress 2.3 -
wordpress wordpress 2.0.9 -
wordpress wordpress 2.3.2 -
wordpress wordpress 2.3.3
wordpress wordpress 2.3.1 -
wordpress wordpress 2.2.3
wordpress wordpress 2.2.2
wordpress wordpress 2.0.7 -
wordpress wordpress 2.1.3 rc2
wordpress wordpress 2.1.3 rc1
wordpress wordpress 2.1 -
wordpress wordpress 2.5 -
wordpress wordpress 2.0.8 -
wordpress wordpress 2.5.1
wordpress wordpress 2.6 -
wordpress wordpress 2.6.1 -
imagely nextgen gallery 2.0.71
wordpress wordpress 2.6.2
wordpress wordpress 2.2.0
wordpress wordpress 2.1 alpha_3
wordpress wordpress 2.3.1 rc1
wordpress wordpress 2.6.5
wordpress wordpress 2.7.1
wordpress wordpress 2.3 rc1
wordpress wordpress 2.3 beta3
wordpress wordpress 2.2
wordpress wordpress 2.2
wordpress wordpress 2.1.3 rc2
wordpress wordpress 2.1.3 rc1
wordpress wordpress 2.6.3
wordpress wordpress 2.8.1 -
wordpress wordpress 2.8.2
wordpress wordpress 2.8.3
wordpress wordpress 2.2
wordpress wordpress 2.2
wordpress wordpress 2.8.1 rc1
wordpress wordpress 2.8.1 beta1
wordpress wordpress 2.8 beta1
wordpress wordpress 2.8.1 beta2
wordpress wordpress 2.8.1 jazzes_themes_and_widgets
wordpress wordpress 2.7 -
wordpress wordpress 2.8
wordpress wordpress 2.8 -
wordpress wordpress 2.8.2
wordpress wordpress 2.0.7 rc1
wordpress wordpress 2.0.7 rc2
wordpress wordpress 2.0.8 rc1
wordpress wordpress 2.0.9 beta
wordpress wordpress 2.0.9rc1
wordpress wordpress 2.1 beta1
wordpress wordpress 2.1 beta2
wordpress wordpress 2.1 beta3
wordpress wordpress 2.1 beta4
wordpress wordpress 2.1 rc1
wordpress wordpress 2.1 rc2
wordpress wordpress 2.1.1beta
wordpress wordpress 2.1.1 rc1
wordpress wordpress 2.1.3 rc3
wordpress wordpress 2.2 rc1
wordpress wordpress 2.2 rc2
wordpress wordpress 2.3 beta2
wordpress wordpress 2.3 beta1
wordpress wordpress 2.3.1 beta1
wordpress wordpress 2.3.2 beta
wordpress wordpress 2.3.2 beta2
wordpress wordpress 2.3.2 beta3
wordpress wordpress 2.3.2 rc1
wordpress wordpress 2.5 rc1
wordpress wordpress 2.5 rc2
wordpress wordpress 2.5 rc3
wordpress wordpress 2.7 beta1
wordpress wordpress 2.7 beta2
wordpress wordpress 2.7 beta3
wordpress wordpress 2.7 rc1
wordpress wordpress 2.6 rc1
wordpress wordpress 2.6 beta1
wordpress wordpress 2.6 beta2
wordpress wordpress 2.6 beta3
wordpress wordpress 2.6.1 beta1
wordpress wordpress 2.6.1 beta2
wordpress wordpress 2.7 rc2
wordpress wordpress 2.7.1 rc1
wordpress wordpress 2.7.1 beta1
wordpress wordpress 2.7.1 rc1
wordpress wordpress 2.8 beta2
wordpress wordpress 2.8 rc1
wordpress wordpress 2.7 coltrane
wordpress wordpress 2.8.4
wordpress wordpress 2.8.5 -
wordpress wordpress 2.9 -
wordpress wordpress 2.9.2