4.9
CVSSv2

CVE-2009-2334

Published: 10/07/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 495
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

wp-admin/admin.php in WordPress and WordPress MU prior to 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote malicious users to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress 2.3.3

wordpress wordpress 2.3.2

wordpress wordpress 2.2.2

wordpress wordpress 2.2.1

wordpress wordpress 2.1.1

wordpress wordpress 2.1

wordpress wordpress 2.6

wordpress wordpress 2.3.1

wordpress wordpress 2.2.0

wordpress wordpress 2.2

wordpress wordpress 2.0.9

wordpress wordpress 2.0.8

wordpress wordpress 2.0.11

wordpress wordpress 2.0.10_rc2

wordpress wordpress 1.5.1.3

wordpress wordpress 1.5.1.2

wordpress wordpress 1.2.2

wordpress wordpress 1.2.1

wordpress wordpress 2.5.1

wordpress wordpress 2.5

wordpress wordpress 2.3

wordpress wordpress 2.2_revision5003

wordpress wordpress 2.1.3_rc2

wordpress wordpress 2.1.3_rc1

wordpress wordpress 2.0.7

wordpress wordpress 2.0.6

wordpress wordpress 2.0.10_rc1

wordpress wordpress 2.0.10

wordpress wordpress 1.5.1.1

wordpress wordpress 1.5.1

wordpress wordpress 1.5-strayhorn

wordpress wordpress 1.2-mingus

wordpress wordpress 1.2-delta

wordpress wordpress 1.0.2

wordpress wordpress 1.0.1-miles

wordpress wordpress 0.711

wordpress wordpress 0.71-gold

wordpress wordpress 2.6.1

wordpress wordpress 2.6.3

wordpress wordpress mu 1.2.4

wordpress wordpress mu 2.6

wordpress wordpress mu 2.6.1

wordpress wordpress 2.0.3

wordpress wordpress 2.0.2

wordpress wordpress 1.6

wordpress wordpress 1.5.2

wordpress wordpress 1.3.1

wordpress wordpress 1.2

wordpress wordpress 1.0

wordpress wordpress 0.72

wordpress wordpress 0.6.2

wordpress wordpress 0.6.2.1

wordpress wordpress mu 1.2

wordpress wordpress mu 1.2.1

wordpress wordpress mu 1.3.1

wordpress wordpress mu 1.3.2

wordpress wordpress mu 1.3.3

wordpress wordpress mu 2.6.5

wordpress wordpress mu

wordpress wordpress 1.0.2-blakey

wordpress wordpress mu 1.2.2

wordpress wordpress mu 1.2.3

wordpress wordpress mu 1.5.1

wordpress wordpress mu 1.5

wordpress wordpress

wordpress wordpress 2.6.5

wordpress wordpress 2.2_revision5002

wordpress wordpress 2.2.3

wordpress wordpress 2.1.3

wordpress wordpress 2.1.2

wordpress wordpress 2.0.5

wordpress wordpress 2.0.4

wordpress wordpress 2.0.1

wordpress wordpress 2.0

wordpress wordpress 1.5

wordpress wordpress 1.4

wordpress wordpress 1.0.1

wordpress wordpress 1.0-platinum

wordpress wordpress 0.71

wordpress wordpress 0.7

wordpress wordpress mu 1.1

wordpress wordpress mu 1.1.1

wordpress wordpress mu 1.2.5a

wordpress wordpress mu 1.3

wordpress wordpress mu 2.6.2

wordpress wordpress mu 2.6.3

Vendor Advisories

Several vulnerabilities have been discovered in wordpress, weblog manager The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-6762 It was discovered that wordpress is prone to an open redirect vulnerability which allows remote attackers to conduct phishing atacks CVE-2008-6767 It was discovered that remot ...
Debian Bug report logs - #504771 wordpress can be subject of delayed attacks via cookies Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Raphael Geissert <atomo64@gmailcom> Date: Fri, 7 Nov 2008 02:42:04 UTC S ...
Debian Bug report logs - #536724 wordpress: CORE-2009-0515 priviledges unchecked and multiple information disclosures Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom&g ...
Debian Bug report logs - #537146 CVE-2009-2431, CVE-2009-2432 Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <giuseppe@iuculanoit> Date: Wed, 15 Jul 2009 14:00:02 UTC Severity: important Tags ...
Debian Bug report logs - #531736 CVE-2008-6767, CVE-2008-6762 Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <giuseppe@iuculanoit> Date: Wed, 3 Jun 2009 17:27:02 UTC Severity: normal Tags: s ...

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Core Security Technologies - CoreLabs Advisory wwwcoresecuritycom/corelabs/ WordPress Privileges Unchecked in adminphp and Multiple Information Disclosures 1 *Advisory Information* Title: WordPress Privileges Unchecked in adminphp and Multiple Information Disclosures A ...
Core Security Technologies Advisory - A vulnerability was found in the way that WordPress handles some URL requests This results in unprivileged users viewing the content of plugins configuration pages, and also in some plugins modifying plugin options and injecting JavaScript code Arbitrary native code may be run by a malicious attacker if the b ...