Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-2146

Опубликовано: 12 мая 2008
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

feisty

ignored

end of life, was needed
gutsy

ignored

end of life, was needed
hardy

not-affected

intrepid

not-affected

jaunty

not-affected

karmic

not-affected

upstream

released

2.2.3

Показывать по

Ссылки на источники

EPSS

Процентиль: 85%
0.02734
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
около 18 лет назад

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

debian
около 18 лет назад

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extra ...

github
около 4 лет назад

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

EPSS

Процентиль: 85%
0.02734
Низкий

7.5 High

CVSS2