PT-2014-8807 · WordPress · Wordpress

Jouko Pynnonen

·

Publicado

2014-11-25

·

Atualizado

2016-06-30

·

CVE-2014-9037

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 3.7.5 WordPress versions 3.8.x prior to 3.8.5 WordPress versions 3.9.x prior to 3.9.3 WordPress versions 4.x prior to 4.0.1
Description The issue allows remote attackers to obtain access to an account that has been idle since 2008. This is possible due to an improper PHP dynamic type comparison for an MD5 hash.
Recommendations For WordPress versions prior to 3.7.5, update to version 3.7.5 or later. For WordPress versions 3.8.x prior to 3.8.5, update to version 3.8.5 or later. For WordPress versions 3.9.x prior to 3.9.3, update to version 3.9.3 or later. For WordPress versions 4.x prior to 4.0.1, update to version 4.0.1 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9037
DLA-236-1
DSA-3085-1
MGASA-2014-0493

Produtos afetados

Wordpress