WordPress Core <= 2.0.3 - Denial of Service
2006-07-29 00:00
AnonymousStrategic Overview
StatusPatched in 2.0.4
Affected CoreWordPress 2.0
Affected Version
<= 2.0.3CVSS6.5Medium
CVE
CVE-2008-0194Vulnerability Overview
Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. NOTE: this might be the same as CVE-2006-5705.1.
Technical Analysis
REMEDIATION: Update to version 2.0.4, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C