CVE-2007-1622
published 2007-03-23CVE-2007-1622: Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.78%
92.3th percentile
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.2.2-1 (bookworm) | wordpress 2.2.2-1 (bookworm) |
| debian | wordpress | < wordpress 2.1.3-1 (bookworm) | wordpress 2.1.3-1 (bookworm) |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 2.2.2-1 | 2.2.2-1 |
| wordpress | wordpress | >= 0 < 2.1.3-1 | 2.1.3-1 |
| wordpress | wordpress | >= 0 < 2.2.2-1 | 2.2.2-1 |
| wordpress | wordpress | >= 0 < 2.1.3-1 | 2.1.3-1 |
| wordpress | wordpress | >= 0 < 2.2.2-1 | 2.2.2-1 |
| wordpress | wordpress | >= 0 < 2.1.3-1 | 2.1.3-1 |
| wordpress | wordpress | >= 0 < 2.2.2-1 | 2.2.2-1 |
| wordpress | wordpress | >= 0 < 2.1.3-1 | 2.1.3-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vrh3-hvpj-7864: Cross-site scripting (XSS) vulnerability in sidebar
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-2627 [MEDIUM] GHSA-vrh3-hvpj-7864: Cross-site scripting (XSS) vulnerability in sidebar
Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.
GHSA
GHSA-m9f5-gr48-mmfx: Cross-site scripting (XSS) vulnerability in wp-admin/vars
ghsa_unreviewed·2022-05-01
CVE-2007-1622 [MEDIUM] GHSA-m9f5-gr48-mmfx: Cross-site scripting (XSS) vulnerability in wp-admin/vars
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF.
GHSA
GHSA-2hmc-pm44-rgw4: Cross-site scripting (XSS) vulnerability in functions
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-3238 [MEDIUM] GHSA-2hmc-pm44-rgw4: Cross-site scripting (XSS) vulnerability in functions
Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.
OSV
CVE-2007-3238: Cross-site scripting (XSS) vulnerability in functions
osv·2007-06-15·CVSS 4.3
CVE-2007-3238 [MEDIUM] CVE-2007-3238: Cross-site scripting (XSS) vulnerability in functions
Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.
OSV
CVE-2007-2627: Cross-site scripting (XSS) vulnerability in sidebar
osv·2007-05-11·CVSS 4.3
CVE-2007-2627 [MEDIUM] CVE-2007-2627: Cross-site scripting (XSS) vulnerability in sidebar
Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.
OSV
CVE-2007-1622: Cross-site scripting (XSS) vulnerability in wp-admin/vars
osv·2007-03-23·CVSS 4.3
CVE-2007-1622 [MEDIUM] CVE-2007-1622: Cross-site scripting (XSS) vulnerability in wp-admin/vars
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF.
Debian
CVE-2007-2627: wordpress - Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custo...
vendor_debian·2007·CVSS 4.3
CVE-2007-2627 [MEDIUM] CVE-2007-2627: wordpress - Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custo...
Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.
Scope: local
bookworm: resolved (fixed in 2.2.2-1)
bullseye: resolved (fixed in 2.2.2-1)
forky: resolved (fixed in 2.2.2-1)
sid: resolved (fixed in 2.2.2-1)
trixie: resolved (fixed in 2.2.2-1)
Debian
CVE-2007-3238: wordpress - Cross-site scripting (XSS) vulnerability in functions.php in the default theme i...
vendor_debian·2007·CVSS 4.3
CVE-2007-3238 [MEDIUM] CVE-2007-3238: wordpress - Cross-site scripting (XSS) vulnerability in functions.php in the default theme i...
Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.
Scope: local
bookworm: resolved (fixed in 2.2.2-1)
bullseye: resolved (fixed in 2.2.2-1)
forky: resolved (fixed in 2.2.2-1)
sid: resolved (fixed in 2.2.2-1)
trixie: resolved (fixed in 2.2.2-1)
Debian
CVE-2007-1622: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress befor...
vendor_debian·2007·CVSS 4.3
CVE-2007-1622 [MEDIUM] CVE-2007-1622: wordpress - Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress befor...
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF.
Scope: local
bookworm: resolved (fixed in 2.1.3-1)
bullseye: resolved (fixed in 2.1.3-1)
forky: resolved (fixed in 2.1.3-1)
sid: resolved (fixed in 2.1.3-1)
trixie: resolved (fixed in 2.1.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-2627: wordpress sidebar.php XSS
bugzilla·2007-05-12·CVSS 4.3
CVE-2007-2627 [MEDIUM] CVE-2007-2627: wordpress sidebar.php XSS
CVE-2007-2627: wordpress sidebar.php XSS
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2627
"Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when
custom 404 pages that call get_sidebar are used, allows remote attackers to
inject arbitrary web script or HTML via the query string (PHP_SELF), a different
vulnerability than CVE-2007-1622."
Discussion:
Upstream doesn't seem to have a patch for this as of yet (May 17 2007).
---
wordpress-2.2.1-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-1599, CVE-2007-1622: wordpress vulnerabilities
bugzilla·2007-03-23·CVSS 6.5
CVE-2007-1599 [MEDIUM] CVE-2007-1599, CVE-2007-1622: wordpress vulnerabilities
CVE-2007-1599, CVE-2007-1622: wordpress vulnerabilities
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1599
"wp-login.php in WordPress allows remote attackers to redirect authenticated
users to other websites and potentially obtain sensitive information via the
redirect_to parameter."
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1622
"Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress
before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote
authenticated users with theme privileges to inject arbitrary web script or HTML
via the PATH_INFO in the administration interface, related to loose regular
expression processing of PHP_SELF."
Discussion:
2.1.3-RC2 packages built - look for 2.1.3-0.rc2 in FC-[5,6], F7
http://secunia.com/advisories/24567http://secunia.com/advisories/25108http://sla.ckers.org/forum/read.php?2%2C7935#msg-8006http://www.buayacorp.com/files/wordpress/wordpress-advisory.txthttp://www.debian.org/security/2007/dsa-1285http://www.securityfocus.com/bid/23027http://www.vupen.com/english/advisories/2007/1005http://secunia.com/advisories/24567http://secunia.com/advisories/25108http://sla.ckers.org/forum/read.php?2%2C7935#msg-8006http://www.buayacorp.com/files/wordpress/wordpress-advisory.txthttp://www.debian.org/security/2007/dsa-1285http://www.securityfocus.com/bid/23027http://www.vupen.com/english/advisories/2007/1005
2007-03-23
Published