[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3328-1 wordpress -- wordpress

ID: oval:org.secpod.oval:def:602189Date: (C)2015-08-28   (M)2021-11-08
Class: PATCHFamily: unix




Several vulnerabilities have been found in Wordpress, the popular blogging engine. CVE-2015-3429 The file example.html in the Genericicons icon font package and twentyfifteen Wordpress theme allowed for cross site scripting. CVE-2015-5622 The robustness of the shortcodes HTML tags filter has been improved. The parsing is a bit more strict, which may affect your installation. CVE-2015-5623 A cross site scripting vulnerability allowed users with the Contributor or Author role to elevate their privileges. The oldstable distribution is only affected by CVE-2015-5622. This less critical issue will be fixed at a later time.

Platform:
Debian 8.x
Product:
wordpress
Reference:
DSA-3328-1
CVE-2015-3429
CVE-2015-5622
CVE-2015-5623
CVE    3
CVE-2015-3429
CVE-2015-5622
CVE-2015-5623
CPE    4
cpe:/a:wordpress:wordpress
cpe:/a:wordpress:wordpress:4.2.2
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies