Extension WordPress
Vulnérabilités Disqus Comment System
Cette page rassemble les failles publiées pour Disqus Comment System, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Disqus Comment System
5 fiches
Disqus Comment System < 2.79 – Multiple Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.79 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) activate or (2) deactivate the plugin via the active…
[*, 2.79)
2.79
17/09/2014
Disqus Comment System < 2.76 – Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) disqus_replace, (2)…
[*, 2.76)
2.76
12/08/2014
Disqus Comment System < 2.76 – Remote Code Execution
The Disqus Comment System plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.75 via the 'getNextToken()' function that parsed user supplied data through the eval() function. This allows unauthenticated attackers to…
[*, 2.76)
2.76
20/06/2014
Disqus Comment System < 2.76 – Reflected Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.
[*, 2.76)
2.76
09/06/2014
Disqus Comment System < 2.68 – Reflected Cross-Site Scripting
The Disqus Comment System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the User-Agent HTTP Header in versions before 2.68 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
[*, 2.68)
2.68
11/12/2011
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.