Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-1277

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.846
EPSS Ranking 99.3%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2007-1277


Contact Us

Shodan ® - All rights reserved