[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-0701Date: (C)2011-03-14   (M)2023-12-22


wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.0
Exploit Score: 8.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECUNIA-43729
BID-46249
ADV-2011-0658
ADV-2011-0721
DSA-2190
FEDORA-2011-3408
FEDORA-2011-3738
FEDORA-2011-3746
http://openwall.com/lists/oss-security/2011/02/08/7
http://openwall.com/lists/oss-security/2011/02/09/13
http://codex.wordpress.org/Version_3.0.5
http://core.trac.wordpress.org/changeset/17393
http://www.wordpress.org/news/2011/02/wordpress-3-0-5/

CPE    1
cpe:/a:wordpress:wordpress
CWE    1
CWE-200
OVAL    11
oval:org.secpod.oval:def:104150
oval:org.secpod.oval:def:101335
oval:org.secpod.oval:def:101337
oval:org.secpod.oval:def:104147
...

© SecPod Technologies