CVE-2011-0700
published 2011-03-14CVE-2011-0700: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
2.67%
84.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.0.5+dfsg-1 (bookworm) | wordpress 3.0.5+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.0.4 | — |
| wordpress | wordpress | >= 0 < 3.0.5+dfsg-1 | 3.0.5+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.0.5+dfsg-1 | 3.0.5+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.0.5+dfsg-1 | 3.0.5+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.0.5+dfsg-1 | 3.0.5+dfsg-1 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f63w-32jx-r3r8: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3
ghsa_unreviewed·2022-05-17
CVE-2011-0700 [LOW] CWE-79 GHSA-f63w-32jx-r3r8: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.
OSV
CVE-2011-0700: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3
osv·2011-03-14·CVSS 3.5
CVE-2011-0700 [LOW] CVE-2011-0700: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.
Debian
CVE-2011-0700: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 al...
vendor_debian·2011·CVSS 3.5
CVE-2011-0700 [LOW] CVE-2011-0700: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 al...
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.
Scope: local
bookworm: resolved (fixed in 3.0.5+dfsg-1)
bullseye: resolved (fixed in 3.0.5+dfsg-1)
forky: resolved (fixed in 3.0.5+dfsg-1)
sid: resolved (fixed in 3.0.5+dfsg-1)
trixie: resolved (fixed in 3.0.5+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2916 freenx-client: qtnx stores configuration, including non-default authentication key, with insecure permissions
bugzilla·2011-08-11·CVSS 5.5
CVE-2011-2916 [MEDIUM] CVE-2011-2916 freenx-client: qtnx stores configuration, including non-default authentication key, with insecure permissions
CVE-2011-2916 freenx-client: qtnx stores configuration, including non-default authentication key, with insecure permissions
It was reported [1] that the qtnx client would store non-custom SSH keys in a world-readable configuration file. If a user did not have a properly secured home directory (if it was world-readable or world-executable), this could allow other users on the local system to obtain the private key used to connect to remote NX sessions.
For example:
% ls -al .qtnx
total 12
drwxrwxr-x. 2 user user 4096 Aug 11 11:36 .
drwxr-x---. 27 user user 4096 Aug 11 11:37 ..
-rw-rw-r--. 1 user user 1209 Aug 11 11:40 cerb.nxml
% grep Auth .qtnx/cerb.nxml
qtnx should probably set the permissions of the *.nxml files to 0600, or the ~/.qtnx/ directory should be mode 0700 (like ~/.ssh/)
Bugzilla
CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [epel-5]
bugzilla·2011-03-15·CVSS 3.5
CVE-2011-0700 [LOW] CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [epel-5]
CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [epel-5]
epel-5 tracking bug for wordpress-mu: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Deprecated, being removed.
https://fedorahosted.org/rel-eng/ticket/5993
Bugzilla
CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [fedora-all]
bugzilla·2011-03-15·CVSS 3.5
CVE-2011-0700 [LOW] CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [fedora-all]
CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=687906
Please note: this i
Bugzilla
CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [epel-all]
bugzilla·2011-03-15·CVSS 3.5
CVE-2011-0700 [LOW] CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [epel-all]
CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=687906
Please note: this iss
Bugzilla
CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [fedora-all]
bugzilla·2011-03-15·CVSS 3.5
CVE-2011-0700 [LOW] CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [fedora-all]
CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=687906
Please note: this i
Bugzilla
CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5
bugzilla·2011-03-15·CVSS 3.5
CVE-2011-0700 [LOW] CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5
CVE-2011-0700 CVE-2011-0701 wordpress: multiple vulnerabilities corrected in 3.0.5
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0700 to
the following vulnerability:
Name: CVE-2011-0700
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0700
Assigned: 20110131
Reference: http://openwall.com/lists/oss-security/2011/02/08/7
Reference: http://openwall.com/lists/oss-security/2011/02/09/13
Reference: http://codex.wordpress.org/Version_3.0.5
Reference: http://core.trac.wordpress.org/changeset/17397
Reference: http://core.trac.wordpress.org/changeset/17401
Reference: http://core.trac.wordpress.org/changeset/17406
Reference: http://core.trac.wordpress.org/changeset/17412
Reference: http://www.wordpress.org/news/2011/02/wordpress-3-0-5/
Reference: http://www.securi
arXiv
Cleaning the NVD: Comprehensive Quality Assessment, Improvements, and Analyses
arxiv_fulltext·2020-06-26
Cleaning the NVD: Comprehensive Quality Assessment, Improvements, and Analyses
[Cleaning the NVD]Cleaning the NVD: Comprehensive Quality Assessment, Improvements, and Analyses
Afsah Anwar
University of Central Florida
[email protected]
Ahmed Abusnaina
University of Central Florida
[email protected]
Songqing Chen
George Mason University
[email protected]
Frank Li
Georgia Institute of Technology
[email protected]
David Mohaisen
University of Central Florida
[email protected]
## Abstract
Vulnerability databases are vital sources of information on emergent software security concerns. Security professionals, from system administrators to developers to researchers, heavily depend on these databases to track vulnerabilities and analyze security trends. How reliable and accurate are these databases though?
In this paper, we explore this questio
http://codex.wordpress.org/Version_3.0.5http://core.trac.wordpress.org/changeset/17397http://core.trac.wordpress.org/changeset/17401http://core.trac.wordpress.org/changeset/17406http://core.trac.wordpress.org/changeset/17412http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056412.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056998.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/057003.htmlhttp://openwall.com/lists/oss-security/2011/02/08/7http://openwall.com/lists/oss-security/2011/02/09/13http://secunia.com/advisories/43729http://www.debian.org/security/2011/dsa-2190http://www.securityfocus.com/bid/46249http://www.vupen.com/english/advisories/2011/0658http://www.vupen.com/english/advisories/2011/0721http://www.wordpress.org/news/2011/02/wordpress-3-0-5/http://codex.wordpress.org/Version_3.0.5http://core.trac.wordpress.org/changeset/17397http://core.trac.wordpress.org/changeset/17401http://core.trac.wordpress.org/changeset/17406http://core.trac.wordpress.org/changeset/17412http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056412.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056998.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/057003.htmlhttp://openwall.com/lists/oss-security/2011/02/08/7http://openwall.com/lists/oss-security/2011/02/09/13http://secunia.com/advisories/43729http://www.debian.org/security/2011/dsa-2190http://www.securityfocus.com/bid/46249http://www.vupen.com/english/advisories/2011/0658http://www.vupen.com/english/advisories/2011/0721http://www.wordpress.org/news/2011/02/wordpress-3-0-5/
2011-03-14
Published