WordPress 'get_edit_post_link()' & 'get_edit_comment_link()' Multiple Eavesdropping Vulnerabilities
BID:30750
Info
WordPress 'get_edit_post_link()' & 'get_edit_comment_link()' Multiple Eavesdropping Vulnerabilities
| Bugtraq ID: | 30750 |
| Class: | Design Error |
| CVE: |
CVE-2008-3747 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2008 12:00AM |
| Updated: | Aug 28 2008 04:34PM |
| Credit: | Robert Accettura |
| Vulnerable: |
WordPress WordPress 2.6.1 WordPress WordPress 2.5.1 WordPress WordPress 2.3.3 WordPress WordPress 2.3.2 WordPress WordPress 2.3.1 WordPress WordPress 2.2.3 WordPress WordPress 2.2.2 WordPress WordPress 2.2.1 WordPress WordPress 2.2.1 WordPress WordPress 2.1.3 WordPress WordPress 2.1.3 WordPress WordPress 2.1.2 WordPress WordPress 2.1.1 WordPress WordPress 2.0.11 WordPress WordPress 2.0.10 WordPress WordPress 2.0.7 WordPress WordPress 2.0.6 WordPress WordPress 2.0.5 WordPress WordPress 2.0.4 WordPress WordPress 2.0.3 WordPress WordPress 2.0.2 WordPress WordPress 2.0.1 WordPress WordPress 2.0 WordPress WordPress 2.6 WordPress WordPress 2.5 WordPress WordPress 2.3 WordPress WordPress 2.2 Revision 5003 WordPress WordPress 2.2 Revision 5002 WordPress WordPress 2.2 WordPress WordPress 2.1.3-RC2 WordPress WordPress 2.1.3-RC1 WordPress WordPress 2.1 WordPress WordPress 2.0.10-RC2 WordPress WordPress 2.0.10-RC1 |
| Not Vulnerable: | |
Discussion
WordPress 'get_edit_post_link()' & 'get_edit_comment_link()' Multiple Eavesdropping Vulnerabilities
WordPress is a prone to multiple eavesdropping vulnerabilities.
Successfully exploiting these issues will allow attackers to obtain sensitive information and possibly to impersonate users and tamper with network data.
Versions prior to WordPress 2.6.1 are vulnerable.
WordPress is a prone to multiple eavesdropping vulnerabilities.
Successfully exploiting these issues will allow attackers to obtain sensitive information and possibly to impersonate users and tamper with network data.
Versions prior to WordPress 2.6.1 are vulnerable.
Exploit / POC
WordPress 'get_edit_post_link()' & 'get_edit_comment_link()' Multiple Eavesdropping Vulnerabilities
An attacker can exploit this issue by using readily available network utilities.
An attacker can exploit this issue by using readily available network utilities.
Solution / Fix
WordPress 'get_edit_post_link()' & 'get_edit_comment_link()' Multiple Eavesdropping Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
WordPress WordPress 2.5
WordPress WordPress 2.1
WordPress WordPress 2.2
WordPress WordPress 2.1.3-RC1
WordPress WordPress 2.6
WordPress WordPress 2.0.10-RC1
WordPress WordPress 2.2 Revision 5003
WordPress WordPress 2.3
WordPress WordPress 2.0.10-RC2
WordPress WordPress 2.2 Revision 5002
WordPress WordPress 2.1.3-RC2
WordPress WordPress 2.0
WordPress WordPress 2.0.1
WordPress WordPress 2.0.10
WordPress WordPress 2.0.11
WordPress WordPress 2.0.2
WordPress WordPress 2.0.3
WordPress WordPress 2.0.4
WordPress WordPress 2.0.5
WordPress WordPress 2.0.6
WordPress WordPress 2.0.7
WordPress WordPress 2.1.1
WordPress WordPress 2.1.2
WordPress WordPress 2.1.3
WordPress WordPress 2.1.3
WordPress WordPress 2.2.1
WordPress WordPress 2.2.1
WordPress WordPress 2.2.2
WordPress WordPress 2.2.3
WordPress WordPress 2.3.1
WordPress WordPress 2.3.2
WordPress WordPress 2.3.3
WordPress WordPress 2.5.1
Solution:
The vendor has released an update. Please see the references for more information.
WordPress WordPress 2.5
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.1
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.2
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.1.3-RC1
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.6
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.10-RC1
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.2 Revision 5003
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.3
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.10-RC2
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.2 Revision 5002
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.1.3-RC2
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.1
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.10
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.11
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.2
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.3
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.4
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.5
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.6
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.0.7
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.1.1
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.1.2
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.1.3
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.1.3
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.2.1
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.2.1
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.2.2
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.2.3
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.3.1
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.3.2
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.3.3
-
WordPress latest.zip
http://wordpress.org/latest.zip
WordPress WordPress 2.5.1
-
WordPress latest.zip
http://wordpress.org/latest.zip
References
WordPress 'get_edit_post_link()' & 'get_edit_comment_link()' Multiple Eavesdropping Vulnerabilities
References:
References: