PT-2009-4848 · WordPress · Wordpress

Publicado

2009-07-10

·

Atualizado

2018-10-10

·

CVE-2009-2431

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress version 2.7.1
Description The issue allows remote attackers to obtain sensitive information by reading the HTML source, specifically the username of a post's author, which is placed in an HTML comment.
Recommendations For WordPress version 2.7.1, consider updating to a newer version that does not include this sensitive information in HTML comments, or manually remove the username from the HTML source to prevent information disclosure.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2431

Produtos afetados

Wordpress