|
|

CVE Reference: CVE-2008-1930 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2008-1930 |
|
|
Description: The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/42027 ST 1019923 SAID Secunia Advisory: SA29965 MISC http://www.cl.cam.ac.uk/users/sjm217/advisories/wordpress-cookie-integrity.txt CONFIRM http://wordpress.org/development/2008/04/wordpress-251/ BUGTRAQ http://www.securityfocus.com/archive/1/archive/1/491356/100/0/threaded BID 28935 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |