WordPress Core < 2.2.3 - Restriction Bypass

2007-09-08 00:00
Anonymous

Strategic Overview

Status
Patched in 2.2.3
Affected CoreWordPress 2.2
Affected Version<= 2.2.2
CVSS5.3Medium
CVECVE-2008-2146
View all WordPress 2.2 vulnerabilities

Vulnerability Overview

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

Technical Analysis

REMEDIATION: Update to version 2.2.3, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C