4.9
CVE-2009-2334
- EPSS 13.97%
- Veröffentlicht 10.07.2009 21:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wordpress ≫ Wordpress Mu Version <= 2.7
Wordpress ≫ Wordpress Mu Version1.1
Wordpress ≫ Wordpress Mu Version1.1.1
Wordpress ≫ Wordpress Mu Version1.2
Wordpress ≫ Wordpress Mu Version1.2.1
Wordpress ≫ Wordpress Mu Version1.2.2
Wordpress ≫ Wordpress Mu Version1.2.3
Wordpress ≫ Wordpress Mu Version1.2.4
Wordpress ≫ Wordpress Mu Version1.2.4 Updaterc1
Wordpress ≫ Wordpress Mu Version1.2.5a
Wordpress ≫ Wordpress Mu Version1.3
Wordpress ≫ Wordpress Mu Version1.3.1
Wordpress ≫ Wordpress Mu Version1.3.2
Wordpress ≫ Wordpress Mu Version1.3.3
Wordpress ≫ Wordpress Mu Version1.5 Updaterc1
Wordpress ≫ Wordpress Mu Version1.5.1
Wordpress ≫ Wordpress Mu Version2.6
Wordpress ≫ Wordpress Mu Version2.6.1
Wordpress ≫ Wordpress Mu Version2.6.2
Wordpress ≫ Wordpress Mu Version2.6.3
Wordpress ≫ Wordpress Mu Version2.6.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 13.97% | 0.941 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 6.8 | 4.9 |
AV:N/AC:M/Au:S/C:P/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.