CVE-2017-6816
published 2017-03-12CVE-2017-6816: In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
PriorityP428medium4.9CVSS 3.0
AVNACLPRHUINSUCNIHAN
EPSS
3.64%
88.3th percentile
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wordpress | < wordpress 4.7.3+dfsg-1 (bookworm) | wordpress 4.7.3+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 4.7.2 | — |
| wordpress | wordpress | >= 0 < 4.7.3+dfsg-1 | 4.7.3+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.7.3+dfsg-1 | 4.7.3+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.7.3+dfsg-1 | 4.7.3+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.7.3+dfsg-1 | 4.7.3+dfsg-1 |
CVSS provenance
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv4.9MEDIUM
vendor_redhat7.1HIGH
vendor_debian4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m2mg-2mqm-rpwh: In WordPress before 4
ghsa_unreviewed·2022-05-13
CVE-2017-6816 [MEDIUM] CWE-863 GHSA-m2mg-2mqm-rpwh: In WordPress before 4
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
OSV
CVE-2017-6816: In WordPress before 4
osv·2017-03-12·CVSS 4.9
CVE-2017-6816 [MEDIUM] CVE-2017-6816: In WordPress before 4
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
Debian
CVE-2017-6816: wordpress - In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be delete...
vendor_debian·2017·CVSS 4.9
CVE-2017-6816 [MEDIUM] CVE-2017-6816: wordpress - In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be delete...
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
Scope: local
bookworm: resolved (fixed in 4.7.3+dfsg-1)
bullseye: resolved (fixed in 4.7.3+dfsg-1)
forky: resolved (fixed in 4.7.3+dfsg-1)
sid: resolved (fixed in 4.7.3+dfsg-1)
trixie: resolved (fixed in 4.7.3+dfsg-1)
Red Hat
tomcat: Infinite loop in the processing of https requests
vendor_redhat·2015-02-06·CVSS 7.1
CVE-2017-6056 [HIGH] CWE-835 tomcat: Infinite loop in the processing of https requests
tomcat: Infinite loop in the processing of https requests
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop.
Statement: This issue was made easier to exploit, causing a denial of service when the patch for CVE-2016-681
No detection rules found.
No writeups or analysis indexed.
http://www.debian.org/security/2017/dsa-3815http://www.securityfocus.com/bid/96598http://www.securitytracker.com/id/1037959https://codex.wordpress.org/Version_4.7.3https://github.com/WordPress/WordPress/commit/4d80f8b3e1b00a3edcee0774dc9c2f4c78f9e663https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/https://wpvulndb.com/vulnerabilities/8767http://www.debian.org/security/2017/dsa-3815http://www.securityfocus.com/bid/96598http://www.securitytracker.com/id/1037959https://codex.wordpress.org/Version_4.7.3https://github.com/WordPress/WordPress/commit/4d80f8b3e1b00a3edcee0774dc9c2f4c78f9e663https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/https://wpvulndb.com/vulnerabilities/8767
2017-03-12
Published