Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: DSA-3384-1 Critical: Joomla XSS and SQL Injection Security Flaws

debian
Calendar Grey October 29, 2015
Debian Logo
- ------------------------------------------------------------------------- Debian Security Advisory
Several vulnerabilities were discovered in Wordpress, a web blogging tool

Summary

CVE-2015-2213

SQL Injection allowed a remote attacker to compromise the site.

CVE-2015-5622

The robustness of the shortcodes HTML tags filter has been improved.
The parsing is a bit more strict, which may affect your
installation.

CVE-2015-5714

A cross-site scripting vulnerability when processing shortcode tags.

CVE-2015-5715

A vulnerability has been discovered, allowing users without proper
permissions to publish private posts and make them sticky.

CVE-2015-5731

An attacker could lock a post that was being edited.

CVE-2015-5732

Cross-site scripting in a widget title allows an attacker to steal
sensitive information.

CVE-2015-5734

Fix some broken links in the legacy theme preview.

CVE-2015-7989

A cross-site scripting vulnerability in user list tables.

For the oldstable distribution (wheezy), these problems have been fixed
in version 3.6.1+dfsg-1~deb7u8.

For the stable distribution (jessie), these problems have been fixed
in version 4.1+dfsg-1+deb8u5 or earli...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: wordpress
CVE ID: CVE-2015-2213 CVE-2015-5622 CVE-2015-5714 CVE-2015-5715

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here