WordPress Core < 2.2.3 - Restriction Bypass
2007-09-08 00:00
AnonymousStrategic Overview
StatusPatched in 2.2.3
Affected CoreWordPress 2.2
Affected Version
<= 2.2.2CVSS5.3Medium
CVE
CVE-2008-2146Vulnerability Overview
wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.
Technical Analysis
REMEDIATION: Update to version 2.2.3, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C