7.8
CVSSv2

CVE-2007-0539

Published: 29/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The wp_remote_fopen function in WordPress prior to 2.1 allows remote malicious users to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

Vendor Advisories

Debian Bug report logs - #407289 CVE-2007-0262: wordpress: Full Path disclosure and disclosure of Table Prefix Weakness Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Alex de Oliveira Silva <enerv@hostsk> Date: ...