Secunia Logo
 
CVE Reference: CVE-2008-2146
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-2146

Description:
wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/42379

OSVDB
  45188

CONFIRM
  http://trac.wordpress.org/changeset?old_path=tags%2F2.2.2&old=6063&new_path=tags%2F2.2.3&new=6063#file10
  http://trac.wordpress.org/ticket/4748
  http://trac.wordpress.org/changeset/6029


Return to the previous page.