PT-2008-5106 · WordPress · Wordpress

Hanno Böck

·

Publicado

2008-08-27

·

Atualizado

2017-08-08

·

CVE-2008-3747

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 2.6.1
Description The issue concerns the get edit post link and get edit comment link functions in WordPress, which do not enforce SSL communication as intended. This could allow remote attackers to gain administrative access by intercepting cookies over the network.
Recommendations For versions prior to 2.6.1, update to version 2.6.1 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3747

Produtos afetados

Wordpress