Описание
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Релиз | Статус | Примечание |
---|---|---|
dapper | ignored | end of life |
devel | not-affected | |
edgy | ignored | end of life, was needs-triage |
feisty | ignored | end of life, was needs-triage |
gutsy | ignored | end of life, was needs-triage |
hardy | ignored | end of life |
intrepid | not-affected | |
jaunty | not-affected | |
karmic | not-affected | |
lucid | not-affected |
Показывать по
Ссылки на источники
EPSS
6.8 Medium
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash o ...
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
EPSS
6.8 Medium
CVSS2
9.8 Critical
CVSS3