7.5
CVSSv2

CVE-2008-3747

Published: 27/08/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress prior to 2.6.1 do not force SSL communication in the intended situations, which might allow remote malicious users to gain administrative access by sniffing the network for a cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress 0.6.2

wordpress wordpress 0.6.2.1

wordpress wordpress 0.72

wordpress wordpress 1.0

wordpress wordpress 1.5.1.3

wordpress wordpress 1.5.2

wordpress wordpress 2.0.6

wordpress wordpress 2.0.7

wordpress wordpress 2.2.1

wordpress wordpress 2.2.2

wordpress wordpress 2.3

wordpress wordpress 2.5

wordpress wordpress 1.2

wordpress wordpress 1.5

wordpress wordpress 2.0.4

wordpress wordpress 2.0.5

wordpress wordpress 2.1.3

wordpress wordpress 2.2

wordpress wordpress 2.3.2

wordpress wordpress 0.711

wordpress wordpress 1.2.1

wordpress wordpress 1.2.2

wordpress wordpress 2.0.10

wordpress wordpress 2.0.11

wordpress wordpress 2.0.2

wordpress wordpress 2.1.1

wordpress wordpress 2.1.2

wordpress wordpress 2.3.1

wordpress wordpress 0.7

wordpress wordpress 0.71

wordpress wordpress 1.0.1

wordpress wordpress 2.0

wordpress wordpress 2.0.1

wordpress wordpress 2.0.9

wordpress wordpress 2.1

wordpress wordpress 2.2.3

wordpress wordpress 2.5.1

wordpress wordpress 2.6

Vendor Advisories

Debian Bug report logs - #497216 wordpress: CVE-2008-3747 information leak, does not always force ssl Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Sat, 30 Aug 2008 22:57:04 U ...