CVE Vulnerabilities

CVE-2009-2853

Published: Aug 18, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress0.71 (including)0.71 (including)
WordpressWordpress0.71-beta (including)0.71-beta (including)
WordpressWordpress0.71-beta_3 (including)0.71-beta_3 (including)
WordpressWordpress0.72 (including)0.72 (including)
WordpressWordpress0.72-beta_1 (including)0.72-beta_1 (including)
WordpressWordpress0.72-beta_2 (including)0.72-beta_2 (including)
WordpressWordpress0.72-rc1 (including)0.72-rc1 (including)
WordpressWordpress0.711 (including)0.711 (including)
WordpressWordpress1.0 (including)1.0 (including)
WordpressWordpress1.0.1-miles (including)1.0.1-miles (including)
WordpressWordpress1.0.1-rc1 (including)1.0.1-rc1 (including)
WordpressWordpress1.2 (including)1.2 (including)
WordpressWordpress1.2-beta (including)1.2-beta (including)
WordpressWordpress1.2-rc1 (including)1.2-rc1 (including)
WordpressWordpress1.2.1 (including)1.2.1 (including)
WordpressWordpress1.2.2 (including)1.2.2 (including)
WordpressWordpress1.5 (including)1.5 (including)
WordpressWordpress1.5.1 (including)1.5.1 (including)
WordpressWordpress1.5.1.3 (including)1.5.1.3 (including)
WordpressWordpress1.5.2 (including)1.5.2 (including)
WordpressWordpress2.0 (including)2.0 (including)
WordpressWordpress2.0.1 (including)2.0.1 (including)
WordpressWordpress2.0.2 (including)2.0.2 (including)
WordpressWordpress2.0.3 (including)2.0.3 (including)
WordpressWordpress2.0.4 (including)2.0.4 (including)
WordpressWordpress2.0.5-ronan (including)2.0.5-ronan (including)
WordpressWordpress2.0.6 (including)2.0.6 (including)
WordpressWordpress2.0.7 (including)2.0.7 (including)
WordpressWordpress2.0.9 (including)2.0.9 (including)
WordpressWordpress2.0.10 (including)2.0.10 (including)
WordpressWordpress2.0.11 (including)2.0.11 (including)
WordpressWordpress2.1-ella (including)2.1-ella (including)
WordpressWordpress2.1.1 (including)2.1.1 (including)
WordpressWordpress2.1.1-dangerous (including)2.1.1-dangerous (including)
WordpressWordpress2.1.2 (including)2.1.2 (including)
WordpressWordpress2.1.3 (including)2.1.3 (including)
WordpressWordpress2.2 (including)2.2 (including)
WordpressWordpress2.2.1 (including)2.2.1 (including)
WordpressWordpress2.2.2 (including)2.2.2 (including)
WordpressWordpress2.2.3 (including)2.2.3 (including)
WordpressWordpress2.3 (including)2.3 (including)
WordpressWordpress2.3-beta3 (including)2.3-beta3 (including)
WordpressWordpress2.3-rc1 (including)2.3-rc1 (including)
WordpressWordpress2.3.1 (including)2.3.1 (including)
WordpressWordpress2.3.1-rc1 (including)2.3.1-rc1 (including)
WordpressWordpress2.3.2 (including)2.3.2 (including)
WordpressWordpress2.5 (including)2.5 (including)
WordpressWordpress2.5.1 (including)2.5.1 (including)
WordpressWordpress2.6 (including)2.6 (including)
WordpressWordpress2.6.1 (including)2.6.1 (including)
WordpressWordpress2.6.2 (including)2.6.2 (including)
WordpressWordpress2.6.3 (including)2.6.3 (including)
WordpressWordpress2.7-coltrane (including)2.7-coltrane (including)
WordpressWordpress2.7.1 (including)2.7.1 (including)
WordpressWordpress2.8 (including)2.8 (including)
WordpressWordpress2.8.1 (including)2.8.1 (including)
WordpressWordpress2.8.2 (including)2.8.2 (including)
WordpressUbuntudapper*
WordpressUbuntuhardy*
WordpressUbuntuintrepid*
WordpressUbuntujaunty*
WordpressUbuntuupstream*

References