7.5

CVE-2008-3747

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WordpressWordpress Version0.6.2
WordpressWordpress Version0.6.2.1
WordpressWordpress Version0.7
WordpressWordpress Version0.71
WordpressWordpress Version0.72
WordpressWordpress Version0.72 Updatebeta1
WordpressWordpress Version0.72 Updatebeta2
WordpressWordpress Version0.72 Updaterc1
WordpressWordpress Version0.711
WordpressWordpress Version1.0
WordpressWordpress Version1.0.1
WordpressWordpress Version1.2
WordpressWordpress Version1.2 Updatebeta
WordpressWordpress Version1.2.1
WordpressWordpress Version1.2.2
WordpressWordpress Version1.5
WordpressWordpress Version1.5.1.3
WordpressWordpress Version1.5.2
WordpressWordpress Version2.0
WordpressWordpress Version2.0.1
WordpressWordpress Version2.0.2
WordpressWordpress Version2.0.4
WordpressWordpress Version2.0.5
WordpressWordpress Version2.0.6
WordpressWordpress Version2.0.7
WordpressWordpress Version2.0.9
WordpressWordpress Version2.0.10
WordpressWordpress Version2.0.11
WordpressWordpress Version2.1
WordpressWordpress Version2.1.1
WordpressWordpress Version2.1.2
WordpressWordpress Version2.1.3
WordpressWordpress Version2.2
WordpressWordpress Version2.2.1
WordpressWordpress Version2.2.2
WordpressWordpress Version2.2.3
WordpressWordpress Version2.3
WordpressWordpress Version2.3 Updatebeta3
WordpressWordpress Version2.3 Updaterc1
WordpressWordpress Version2.3.1
WordpressWordpress Version2.3.1 Updaterc1
WordpressWordpress Version2.3.2
WordpressWordpress Version2.5
WordpressWordpress Version2.5.1
WordpressWordpress Version2.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.45% 0.799
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P