4.9

CVE-2009-2334

Exploit

wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WordpressWordpress Version <= 2.7.1
WordpressWordpress Version0.6.2
WordpressWordpress Version0.6.2 Updatebeta_2
WordpressWordpress Version0.6.2.1
WordpressWordpress Version0.6.2.1 Updatebeta_2
WordpressWordpress Version0.7
WordpressWordpress Version0.71
WordpressWordpress Version0.71-gold
WordpressWordpress Version0.72
WordpressWordpress Version0.72 Updatebeta1
WordpressWordpress Version0.72 Updatebeta2
WordpressWordpress Version0.72 Updaterc1
WordpressWordpress Version0.711
WordpressWordpress Version1.0
WordpressWordpress Version1.0 Updaterc1
WordpressWordpress Version1.0 Updaterc2
WordpressWordpress Version1.0 Updaterc3
WordpressWordpress Version1.0 Updaterc4
WordpressWordpress Version1.0-platinum
WordpressWordpress Version1.0.1
WordpressWordpress Version1.0.1-miles
WordpressWordpress Version1.0.2
WordpressWordpress Version1.0.2-blakey
WordpressWordpress Version1.2
WordpressWordpress Version1.2 Updatebeta
WordpressWordpress Version1.2-delta
WordpressWordpress Version1.2-mingus
WordpressWordpress Version1.2.1
WordpressWordpress Version1.2.2
WordpressWordpress Version1.3.1
WordpressWordpress Version1.4
WordpressWordpress Version1.5
WordpressWordpress Version1.5-strayhorn
WordpressWordpress Version1.5.1
WordpressWordpress Version1.5.1.1
WordpressWordpress Version1.5.1.2
WordpressWordpress Version1.5.1.3
WordpressWordpress Version1.5.2
WordpressWordpress Version1.6
WordpressWordpress Version2.0
WordpressWordpress Version2.0.1
WordpressWordpress Version2.0.2
WordpressWordpress Version2.0.3
WordpressWordpress Version2.0.4
WordpressWordpress Version2.0.5
WordpressWordpress Version2.0.6
WordpressWordpress Version2.0.7
WordpressWordpress Version2.0.8
WordpressWordpress Version2.0.9
WordpressWordpress Version2.0.10
WordpressWordpress Version2.0.10_rc1
WordpressWordpress Version2.0.10_rc2
WordpressWordpress Version2.0.11
WordpressWordpress Version2.1
WordpressWordpress Version2.1 Updatealpha_3
WordpressWordpress Version2.1.1
WordpressWordpress Version2.1.2
WordpressWordpress Version2.1.3
WordpressWordpress Version2.1.3_rc1
WordpressWordpress Version2.1.3_rc2
WordpressWordpress Version2.2
WordpressWordpress Version2.2.0
WordpressWordpress Version2.2.1
WordpressWordpress Version2.2.2
WordpressWordpress Version2.2.3
WordpressWordpress Version2.2_revision5002
WordpressWordpress Version2.2_revision5003
WordpressWordpress Version2.3
WordpressWordpress Version2.3 Updatebeta3
WordpressWordpress Version2.3 Updaterc1
WordpressWordpress Version2.3.1
WordpressWordpress Version2.3.1 Updaterc1
WordpressWordpress Version2.3.2
WordpressWordpress Version2.3.3
WordpressWordpress Version2.5
WordpressWordpress Version2.5.1
WordpressWordpress Version2.6
WordpressWordpress Version2.6.1
WordpressWordpress Version2.6.3
WordpressWordpress Version2.6.5
WordpressWordpress Mu Version <= 2.7
WordpressWordpress Mu Version1.1
WordpressWordpress Mu Version1.1.1
WordpressWordpress Mu Version1.2
WordpressWordpress Mu Version1.2.1
WordpressWordpress Mu Version1.2.2
WordpressWordpress Mu Version1.2.3
WordpressWordpress Mu Version1.2.4
WordpressWordpress Mu Version1.2.4 Updaterc1
WordpressWordpress Mu Version1.2.5a
WordpressWordpress Mu Version1.3
WordpressWordpress Mu Version1.3.1
WordpressWordpress Mu Version1.3.2
WordpressWordpress Mu Version1.3.3
WordpressWordpress Mu Version1.5 Updaterc1
WordpressWordpress Mu Version1.5.1
WordpressWordpress Mu Version2.6
WordpressWordpress Mu Version2.6.1
WordpressWordpress Mu Version2.6.2
WordpressWordpress Mu Version2.6.3
WordpressWordpress Mu Version2.6.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.97% 0.941
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 6.8 4.9
AV:N/AC:M/Au:S/C:P/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.