6.4
CVSSv2

CVE-2014-0166

Published: 10/04/2014 Updated: 16/12/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress prior to 3.7.2 and 3.8.x prior to 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote malicious users to obtain access via a forged cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress 3.6

wordpress wordpress 3.5.1

wordpress wordpress 3.3.1

wordpress wordpress 3.3

wordpress wordpress 3.1

wordpress wordpress 3.0.6

wordpress wordpress 2.9.2

wordpress wordpress 2.9.1.1

wordpress wordpress 2.8.4

wordpress wordpress

wordpress wordpress 3.8

wordpress wordpress 3.4.1

wordpress wordpress 3.4.0

wordpress wordpress 3.1.4

wordpress wordpress 3.1.3

wordpress wordpress 3.0.3

wordpress wordpress 3.0.2

wordpress wordpress 2.8.6

wordpress wordpress 2.8.5.2

wordpress wordpress 2.8

wordpress wordpress 2.7.1

wordpress wordpress 2.5.1

wordpress wordpress 2.5

wordpress wordpress 2.2.1

wordpress wordpress 2.2

wordpress wordpress 2.0.6

wordpress wordpress 2.0.5

wordpress wordpress 1.6.2

wordpress wordpress 1.5.2

wordpress wordpress 1.3.2

wordpress wordpress 1.3

wordpress wordpress 1.1.1

wordpress wordpress 1.0.2

wordpress wordpress 3.8.1

wordpress wordpress 3.6.1

wordpress wordpress 3.3.3

wordpress wordpress 3.3.2

wordpress wordpress 3.1.2

wordpress wordpress 3.1.1

wordpress wordpress 3.0.1

wordpress wordpress 3.0

wordpress wordpress 2.8.5.1

wordpress wordpress 2.8.5

wordpress wordpress 2.7

wordpress wordpress 2.6.5

wordpress wordpress 2.3.3

wordpress wordpress 2.3.2

wordpress wordpress 2.1.3

wordpress wordpress 2.1.2

wordpress wordpress 2.1.1

wordpress wordpress 2.0.4

wordpress wordpress 2.0.2

wordpress wordpress 1.5.1.3

wordpress wordpress 1.5.1.2

wordpress wordpress 1.2.5

wordpress wordpress 1.2.4

wordpress wordpress 1.0.1

wordpress wordpress 1.0

wordpress wordpress 2.8.3

wordpress wordpress 2.6.3

wordpress wordpress 2.6.2

wordpress wordpress 2.3.1

wordpress wordpress 2.3

wordpress wordpress 2.1

wordpress wordpress 2.0.9

wordpress wordpress 2.0.11

wordpress wordpress 2.0.10

wordpress wordpress 1.5.1.1

wordpress wordpress 1.5.1

wordpress wordpress 1.2.3

wordpress wordpress 1.2.2

wordpress wordpress 0.71

wordpress wordpress 3.7

wordpress wordpress 3.5.0

wordpress wordpress 3.4.2

wordpress wordpress 3.2.1

wordpress wordpress 3.2

wordpress wordpress 3.0.5

wordpress wordpress 3.0.4

wordpress wordpress 2.9.1

wordpress wordpress 2.9

wordpress wordpress 2.8.2

wordpress wordpress 2.8.1

wordpress wordpress 2.6.1

wordpress wordpress 2.6

wordpress wordpress 2.2.3

wordpress wordpress 2.2.2

wordpress wordpress 2.0.8

wordpress wordpress 2.0.7

wordpress wordpress 2.0.1

wordpress wordpress 2.0

wordpress wordpress 1.5

wordpress wordpress 1.3.3

wordpress wordpress 1.2.1

wordpress wordpress 1.2

Vendor Advisories

Debian Bug report logs - #744018 Wordpress 382 fixes two vulnerabilities [CVE-2014-0165 CVE-2014-0166] Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Thijs Kinkhorst <thijs@debianorg> Date: Wed, 9 Apr 2014 0 ...
Debian Bug report logs - #744019 CVE-2014-0157: XSS in Horizon orchestration dashboard Package: src:horizon; Maintainer for src:horizon is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Wed, 9 Apr 2014 09:21:01 UTC Severity: important Found in version hori ...

Github Repositories

POC of CVE-2014-0166 (WordPress cookie forgery vulnerability)

##POC&EXP of CVE-2014-0166 ####WordPress < 382 cookie forgery vulnerability Details of this vulnerability can be found at here There are three files: wp_zero_cookie_generatorphp POC to verify this vulnerability It won't send any requests, just a local brute-forcer Redefine variables to supply info and it will try to find out a zero cookie zero