[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-2334Date: (C)2009-07-10   (M)2023-12-22


wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.9
Exploit Score: 6.8
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1022528
http://www.securityfocus.com/archive/1/504795/100/0/threaded
BID-35584
OSVDB-55712
OSVDB-55715
EXPLOIT-DB-9110
ADV-2009-1833
DSA-1871
FEDORA-2009-7701
FEDORA-2009-7729
FEDORA-2009-8529
FEDORA-2009-8538
http://corelabs.coresecurity.com/index.php?action=view&type=advisory&name=WordPress_Privileges_Unchecked
http://wordpress.org/development/2009/07/wordpress-2-8-1/

CPE    43
cpe:/a:wordpress:wordpress:2.6.3
cpe:/a:wordpress:wordpress:2.6.1
cpe:/a:wordpress:wordpress:2.2.3
cpe:/a:wordpress:wordpress:2.2.2
...
CWE    1
CWE-287
OVAL    9
oval:org.secpod.oval:def:101518
oval:org.secpod.oval:def:101511
oval:org.secpod.oval:def:101551
oval:org.mitre.oval:def:8072
...

© SecPod Technologies