WordPress Pingback SourceURI Denial Of Service and Information Disclosure Vulnerability
BID:22220
Info
WordPress Pingback SourceURI Denial Of Service and Information Disclosure Vulnerability
| Bugtraq ID: | 22220 |
| Class: | Design Error |
| CVE: |
CVE-2007-0540 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2007 12:00AM |
| Updated: | May 01 2008 08:46PM |
| Credit: | Blake Matheny discovered these issues. |
| Vulnerable: |
WordPress Wordpress (B2) 0.6.2 .1 WordPress Wordpress (B2) 0.6.2 WordPress WordPress 2.0.7 WordPress WordPress 2.0.6 WordPress WordPress 2.0.5 WordPress WordPress 2.0.4 WordPress WordPress 2.0.3 WordPress WordPress 2.0.2 WordPress WordPress 2.0.1 WordPress WordPress 2.0 WordPress WordPress 1.5.2 WordPress WordPress 1.5.1 .3 WordPress WordPress 1.5.1 .2 WordPress WordPress 1.5.1 WordPress WordPress 1.5 WordPress WordPress 1.2.2 WordPress WordPress 1.2.1 WordPress WordPress 1.2 WordPress WordPress 0.71 WordPress WordPress 0.7 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
WordPress WordPress 2.1 |
Discussion
WordPress Pingback SourceURI Denial Of Service and Information Disclosure Vulnerability
WordPress is prone to a denial-of-service vulnerability and an information-disclosure vulnerability.
Attackers can exploit these issues to consume memory and bandwidth resources, denying service to legitimate users, or to gain information that may aid in further attacks.
Versions prior to WordPress 2.1 are vulnerable.
WordPress is prone to a denial-of-service vulnerability and an information-disclosure vulnerability.
Attackers can exploit these issues to consume memory and bandwidth resources, denying service to legitimate users, or to gain information that may aid in further attacks.
Versions prior to WordPress 2.1 are vulnerable.
Exploit / POC
WordPress Pingback SourceURI Denial Of Service and Information Disclosure Vulnerability
An attacker can exploit these issues via a browser.
The following proof-of-concept POST request is available: (22220.html)
A Python script that conducts a denial-of-service attack is also available: (exploit.py)
An attacker can exploit these issues via a browser.
The following proof-of-concept POST request is available: (22220.html)
A Python script that conducts a denial-of-service attack is also available: (exploit.py)
Solution / Fix
WordPress Pingback SourceURI Denial Of Service and Information Disclosure Vulnerability
Solution:
The vendor has released WordPress 2.1 to address this issue. Please see the references for more information.
WordPress Wordpress (B2) 0.6.2 .1
WordPress Wordpress (B2) 0.6.2
WordPress WordPress 0.7
WordPress WordPress 0.71
WordPress WordPress 1.2
WordPress WordPress 1.2.1
WordPress WordPress 1.2.2
WordPress WordPress 1.5
WordPress WordPress 1.5.1 .3
WordPress WordPress 1.5.1
WordPress WordPress 1.5.1 .2
WordPress WordPress 1.5.2
WordPress WordPress 2.0
WordPress WordPress 2.0.1
WordPress WordPress 2.0.2
WordPress WordPress 2.0.3
WordPress WordPress 2.0.4
WordPress WordPress 2.0.5
WordPress WordPress 2.0.6
WordPress WordPress 2.0.7
Solution:
The vendor has released WordPress 2.1 to address this issue. Please see the references for more information.
WordPress Wordpress (B2) 0.6.2 .1
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress Wordpress (B2) 0.6.2
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 0.7
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 0.71
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.2
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.2.1
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.2.2
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.5
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.5.1 .3
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.5.1
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.5.1 .2
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.5.2
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.1
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.2
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.3
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.4
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.5
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.6
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
WordPress WordPress 2.0.7
-
WordPress latest.tar.gz
http://wordpress.org/latest.tar.gz
References
WordPress Pingback SourceURI Denial Of Service and Information Disclosure Vulnerability
References:
References:
- Pingback DDOS possibility (WordPress Trac)
- WordPress Homepage (WordPress)
- Multiple Remote Vulnerabilities in Wordpress (Blake Matheny)
- Weaknesses in Pingback Design (Blake Matheny)