Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
wordpress REQUEST全局数组跨站请求伪造漏洞
Vulnerability Description
WordPress是一个基于PHP和Mysql的开源的博客发布应用程序。 WordPress 在某些危险情况下依赖REQUEST超全局的数组,这使得远程攻击者更易于借助特制的cookies,执行延迟的和连续的跨站请求伪造攻击。比如借助攻击来(1)删除用户帐户或(2)引起拒绝服务攻击(应用程序访问丢失)。
CVSS Information
N/A
Vulnerability Type
N/A