PT-2014-2061 · WordPress · Wordpress

Henri Salo

·

Publicado

2014-10-27

·

Atualizado

2017-08-29

·

CVE-2003-1599

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WordPress version 0.70
Description A remote file inclusion issue allows attackers to execute arbitrary PHP code via a URL in the abspath variable.
Recommendations For WordPress version 0.70, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the links.all.php file in the wp-links directory until a patch is available. Avoid using the abspath variable in URLs to minimize the risk of exploitation.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2003-1599

Produtos afetados

Wordpress