7.5
CVSSv2

CVE-2007-2821

Published: 22/05/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress prior to 2.2 allows remote malicious users to execute arbitrary SQL commands via the cookie parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

Vendor Advisories

Debian Bug report logs - #437085 CVE-2007-1599: wp-loginphp allows remote attackers to redirect authenticated users to other websites Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@sko ...
Several remote vulnerabilities have been discovered in wordpress, a weblog manager The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-3238 Cross-site scripting (XSS) vulnerability in functionsphp in the default theme in WordPress allows remote authenticated administrators to inject arbitrary ...

Exploits

<?php error_reporting(E_ALL); $norm_delay = 0; /////////////////////////////////////////////////////////////////////// /////////////////////////////////////////////////////////////////////// // WordPress 213 "admin-ajaxphp" sql injection blind fishing exploit // written by Janek Vind "waraxe" // wwwwaraxeus/ // 21 may 2007 ///////// ...

Github Repositories

312codepath, CodePath Week 7 Assignment Logan Louks 11/6/2018 Directions: For this week's assignment, discover and demonstrate similar proofs-of-concept for at least an additional three and (up to five) exploits affecting an older version of WP Submit the write-ups and walkthroughs via Github Check out the Submitting Assignments page for more details Be sure to include