CVE-2007-1277
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 27.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 27.01% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- wordpress/wordpress
- Source
- cve@mitre.org
References
- http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.htmlExploit
- http://secunia.com/advisories/24374Vendor Advisory
- http://wordpress.org/development/2007/03/upgrade-212/Vendor Advisory
- http://www.kb.cert.org/vuls/id/214480US Government Resource
- http://www.kb.cert.org/vuls/id/641456US Government Resource
- http://www.securityfocus.com/archive/1/461794/100/0/threaded
- http://www.securityfocus.com/bid/22797
- http://www.vupen.com/english/advisories/2007/0812
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32804
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32807
- http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.htmlExploit
- http://secunia.com/advisories/24374Vendor Advisory
- http://wordpress.org/development/2007/03/upgrade-212/Vendor Advisory
- http://www.kb.cert.org/vuls/id/214480US Government Resource
- http://www.kb.cert.org/vuls/id/641456US Government Resource
- http://www.securityfocus.com/archive/1/461794/100/0/threaded
- http://www.securityfocus.com/bid/22797
- http://www.vupen.com/english/advisories/2007/0812
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32804
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32807
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.