CVE Vulnerabilities

CVE-2008-3747

Published: Aug 27, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress0.6.2 (including)0.6.2 (including)
WordpressWordpress0.6.2.1 (including)0.6.2.1 (including)
WordpressWordpress0.7 (including)0.7 (including)
WordpressWordpress0.71 (including)0.71 (including)
WordpressWordpress0.72 (including)0.72 (including)
WordpressWordpress0.72-beta1 (including)0.72-beta1 (including)
WordpressWordpress0.72-beta2 (including)0.72-beta2 (including)
WordpressWordpress0.72-rc1 (including)0.72-rc1 (including)
WordpressWordpress0.711 (including)0.711 (including)
WordpressWordpress1.0 (including)1.0 (including)
WordpressWordpress1.0.1 (including)1.0.1 (including)
WordpressWordpress1.2 (including)1.2 (including)
WordpressWordpress1.2-beta (including)1.2-beta (including)
WordpressWordpress1.2.1 (including)1.2.1 (including)
WordpressWordpress1.2.2 (including)1.2.2 (including)
WordpressWordpress1.5 (including)1.5 (including)
WordpressWordpress1.5.1.3 (including)1.5.1.3 (including)
WordpressWordpress1.5.2 (including)1.5.2 (including)
WordpressWordpress2.0 (including)2.0 (including)
WordpressWordpress2.0.1 (including)2.0.1 (including)
WordpressWordpress2.0.2 (including)2.0.2 (including)
WordpressWordpress2.0.4 (including)2.0.4 (including)
WordpressWordpress2.0.5 (including)2.0.5 (including)
WordpressWordpress2.0.6 (including)2.0.6 (including)
WordpressWordpress2.0.7 (including)2.0.7 (including)
WordpressWordpress2.0.9 (including)2.0.9 (including)
WordpressWordpress2.0.10 (including)2.0.10 (including)
WordpressWordpress2.0.11 (including)2.0.11 (including)
WordpressWordpress2.1 (including)2.1 (including)
WordpressWordpress2.1.1 (including)2.1.1 (including)
WordpressWordpress2.1.2 (including)2.1.2 (including)
WordpressWordpress2.1.3 (including)2.1.3 (including)
WordpressWordpress2.2 (including)2.2 (including)
WordpressWordpress2.2.1 (including)2.2.1 (including)
WordpressWordpress2.2.2 (including)2.2.2 (including)
WordpressWordpress2.2.3 (including)2.2.3 (including)
WordpressWordpress2.3 (including)2.3 (including)
WordpressWordpress2.3-beta3 (including)2.3-beta3 (including)
WordpressWordpress2.3-rc1 (including)2.3-rc1 (including)
WordpressWordpress2.3.1 (including)2.3.1 (including)
WordpressWordpress2.3.1-rc1 (including)2.3.1-rc1 (including)
WordpressWordpress2.3.2 (including)2.3.2 (including)
WordpressWordpress2.5 (including)2.5 (including)
WordpressWordpress2.5.1 (including)2.5.1 (including)
WordpressWordpress2.6 (including)2.6 (including)
WordpressUbuntudapper*
WordpressUbuntufeisty*
WordpressUbuntugutsy*
WordpressUbuntuhardy*
WordpressUbuntuintrepid*
WordpressUbuntuupstream*

References