Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-5868

Опубликовано: 27 дек. 2012
Источник: debian
EPSS Низкий

Описание

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressunfixedpackage

Примечания

  • non-issue, see https://wordpress.org/support/topic/old-bug-cve-2012-5868

EPSS

Процентиль: 79%
0.01342
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

nvd
больше 12 лет назад

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

github
около 3 лет назад

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

EPSS

Процентиль: 79%
0.01342
Низкий