CVE Vulnerabilities

CVE-2007-0262

Published: Jan 16, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

Affected Software

Name Vendor Start Version End Version
Wordpress Wordpress 2.0.6 (including) 2.0.6 (including)
Wordpress Wordpress 2.1-alpha_3 (including) 2.1-alpha_3 (including)
Wordpress Ubuntu dapper *
Wordpress Ubuntu edgy *
Wordpress Ubuntu upstream *

References