CVE Vulnerabilities

CVE-2008-2146

Published: May 12, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress*2.2.2 (including)
WordpressWordpress0.6.2 (including)0.6.2 (including)
WordpressWordpress0.6.2.1 (including)0.6.2.1 (including)
WordpressWordpress0.7 (including)0.7 (including)
WordpressWordpress0.71 (including)0.71 (including)
WordpressWordpress0.711 (including)0.711 (including)
WordpressWordpress1.0 (including)1.0 (including)
WordpressWordpress1.0.1 (including)1.0.1 (including)
WordpressWordpress1.0.2 (including)1.0.2 (including)
WordpressWordpress1.2 (including)1.2 (including)
WordpressWordpress1.2.1 (including)1.2.1 (including)
WordpressWordpress1.2.2 (including)1.2.2 (including)
WordpressWordpress1.3.1 (including)1.3.1 (including)
WordpressWordpress1.4 (including)1.4 (including)
WordpressWordpress1.5 (including)1.5 (including)
WordpressWordpress1.5-strayhorn (including)1.5-strayhorn (including)
WordpressWordpress1.5.1 (including)1.5.1 (including)
WordpressWordpress1.5.1.1 (including)1.5.1.1 (including)
WordpressWordpress1.5.1.2 (including)1.5.1.2 (including)
WordpressWordpress1.5.1.3 (including)1.5.1.3 (including)
WordpressWordpress1.5.2 (including)1.5.2 (including)
WordpressWordpress1.6 (including)1.6 (including)
WordpressWordpress2.0 (including)2.0 (including)
WordpressWordpress2.0.1 (including)2.0.1 (including)
WordpressWordpress2.0.2 (including)2.0.2 (including)
WordpressWordpress2.0.3 (including)2.0.3 (including)
WordpressWordpress2.0.4 (including)2.0.4 (including)
WordpressWordpress2.0.5 (including)2.0.5 (including)
WordpressWordpress2.0.6 (including)2.0.6 (including)
WordpressWordpress2.0.7 (including)2.0.7 (including)
WordpressWordpress2.0.8 (including)2.0.8 (including)
WordpressWordpress2.0.9 (including)2.0.9 (including)
WordpressWordpress2.0.10 (including)2.0.10 (including)
WordpressWordpress2.0.10_rc1 (including)2.0.10_rc1 (including)
WordpressWordpress2.0.10_rc2 (including)2.0.10_rc2 (including)
WordpressWordpress2.0.11 (including)2.0.11 (including)
WordpressWordpress2.1 (including)2.1 (including)
WordpressWordpress2.1.1 (including)2.1.1 (including)
WordpressWordpress2.1.2 (including)2.1.2 (including)
WordpressWordpress2.1.3 (including)2.1.3 (including)
WordpressWordpress2.1.3_rc1 (including)2.1.3_rc1 (including)
WordpressWordpress2.1.3_rc2 (including)2.1.3_rc2 (including)
WordpressWordpress2.2 (including)2.2 (including)
WordpressWordpress2.2.0 (including)2.2.0 (including)
WordpressWordpress2.2.1 (including)2.2.1 (including)
WordpressWordpress2.2_revision5002 (including)2.2_revision5002 (including)
WordpressWordpress2.2_revision5003 (including)2.2_revision5003 (including)
WordpressUbuntudapper*
WordpressUbuntufeisty*
WordpressUbuntugutsy*
WordpressUbuntuupstream*

References