6.8
CVE-2014-9037
- EPSS 2.57%
- Veröffentlicht 25.11.2014 23:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Wordpress Core < 4.0.1 - Hash Collision
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
Mögliche Gegenmaßnahme
WordPress: Update to one of the following versions, or a newer patched version: 3.7.5, 3.8.5, 3.9.3, 4.0.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mageia Project ≫ Mageia Version 3
Mageia Project ≫ Mageia Version 4
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Weitere Schwachstelleninformationen
SystemWordPress Core
≫
Produkt
WordPress
Version
[*, 3.7)
Version
3.7-3.7.4
Version
3.8-3.8.4
Version
3.9-3.9.2
Version
4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.57% | 0.831 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://advisories.mageia.org/MGASA-2014-0493.html
http://openwall.com/lists/oss-security/2014/11/25/12
http://www.debian.org/security/2014/dsa-3085
http://www.mandriva.com/security/advisories?name=MDVSA-2014:233
http://www.securitytracker.com/id/1031243
https://wordpress.org/news/2014/11/wordpress-4-0-1/
https://www.wordfence.com/threat-intel/vulnerabilities/id/05873114-ceed-404c-9cc2-d85aa92ef6f3