wordpress: multiple vulnerabilities
| Package(s): | wordpress | CVE #(s): | CVE-2011-0700 CVE-2011-0701 | ||||||||||||
| Created: | March 11, 2011 | Updated: | September 18, 2012 | ||||||||||||
| Description: | From the Debian advisory:
CVE-2011-0700: Input passed via the post title when performing a "Quick Edit" or "Bulk Edit" action and via the "post_status", "comment_status", and "ping_status" parameters is not properly sanitised before being used. Certain input passed via tags in the tags meta-box is not properly sanitised before being returned to the user. CVE-2011-0701: Wordpress incorrectly enforces user access restrictions when accessing posts via the media uploader and can be exploited to disclose the contents of e.g. private or draft posts. | ||||||||||||||
| Alerts: |
| ||||||||||||||
