Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-0541
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-0541

Description:
WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.

CVE Status:
Candidate

References:

SREASON
  http://securityreason.com/securityalert/2191

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/457996/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/458003/100/0/threaded


Return to the previous page.