PT-2008-2137 · Dean · Dean'S Permalinks Migration

G30Rg3_X

·

Publicado

2008-01-31

·

Atualizado

2018-10-15

·

CVE-2008-0508

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dean's Permalinks Migration plugin version 1.0
Description A cross-site request forgery (CSRF) issue allows remote attackers to modify the oldstructure configuration setting, also known as dean pm config[oldstructure], as administrators. This is achieved via the old struct parameter in a deans permalinks migration.php action to wp-admin/options-general.php. An example of exploitation includes placing an XSS sequence in this setting.
Recommendations For Dean's Permalinks Migration plugin version 1.0, consider disabling access to the deans permalinks migration.php file until a patch is available to prevent modification of the oldstructure setting. Restrict access to the wp-admin/options-general.php page to minimize the risk of exploitation. Avoid using the old struct parameter in the affected action until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0508

Produtos afetados

Dean'S Permalinks Migration