|
|
| |
|
| |
wordpress: multiple vulnerabilities
| Package(s): | wordpress |
CVE #(s): | CVE-2011-0700
CVE-2011-0701
|
| Created: | March 11, 2011 |
Updated: | September 18, 2012 |
| Description: |
From the Debian advisory:
CVE-2011-0700: Input passed via the post title when performing a "Quick Edit" or "Bulk Edit" action and via the "post_status", "comment_status", and "ping_status" parameters is not properly sanitised before being used.
Certain input passed via tags in the tags meta-box is not properly sanitised before being returned to the user.
CVE-2011-0701: Wordpress incorrectly enforces user access restrictions when accessing posts via the media uploader and can be exploited to disclose the contents of e.g. private or draft posts.
|
| Alerts: |
|
( Log in to post comments)
|
|
|