Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-2762

Опубликовано: 13 авг. 2009
Источник: nvd
CVSS2: 7.5
EPSS Высокий

Описание

wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
Версия до 2.8.3 (включая)

EPSS

Процентиль: 99%
0.74127
Высокий

7.5 High

CVSS2

Дефекты

CWE-255

Связанные уязвимости

ubuntu
почти 16 лет назад

wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.

debian
почти 16 лет назад

wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to ...

github
больше 3 лет назад

wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.

EPSS

Процентиль: 99%
0.74127
Высокий

7.5 High

CVSS2

Дефекты

CWE-255