CVE-2009-2853
Last modified
CVE-2009-2853 is a vulnerability of currently unknown severity. Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.. EPSS estimates a 4.71% chance of exploitation in the next 30 days.
Description
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Wordpress | Wordpress | 0.71 | — |
| Wordpress | Wordpress | 0.72 | — |
| Wordpress | Wordpress | 0.711 | — |
| Wordpress | Wordpress | 1.0 | — |
| Wordpress | Wordpress | 1.0.1 | Miles |
| Wordpress | Wordpress | 1.2 | — |
| Wordpress | Wordpress | 1.2.1 | — |
| Wordpress | Wordpress | 1.2.2 | — |
| Wordpress | Wordpress | 1.5 | — |
| Wordpress | Wordpress | 1.5.1 | — |
| Wordpress | Wordpress | 1.5.1.3 | — |
| Wordpress | Wordpress | 1.5.2 | — |
| Wordpress | Wordpress | 2.0 | — |
| Wordpress | Wordpress | 2.0.1 | — |
| Wordpress | Wordpress | 2.0.2 | — |
| Wordpress | Wordpress | 2.0.3 | — |
| Wordpress | Wordpress | 2.0.4 | — |
| Wordpress | Wordpress | 2.0.5 | Ronan |
| Wordpress | Wordpress | 2.0.6 | — |
| Wordpress | Wordpress | 2.0.7 | — |
| Wordpress | Wordpress | 2.0.9 | — |
| Wordpress | Wordpress | 2.0.10 | — |
| Wordpress | Wordpress | 2.0.11 | — |
| Wordpress | Wordpress | 2.1 | Ella |
| Wordpress | Wordpress | 2.1.1 | — |
| Wordpress | Wordpress | 2.1.2 | — |
| Wordpress | Wordpress | 2.1.3 | — |
| Wordpress | Wordpress | 2.2 | — |
| Wordpress | Wordpress | 2.2.1 | — |
| Wordpress | Wordpress | 2.2.2 | — |
| Wordpress | Wordpress | 2.2.3 | — |
| Wordpress | Wordpress | 2.3 | — |
| Wordpress | Wordpress | 2.3.1 | — |
| Wordpress | Wordpress | 2.3.2 | — |
| Wordpress | Wordpress | 2.5 | — |
| Wordpress | Wordpress | 2.5.1 | — |
| Wordpress | Wordpress | 2.6 | — |
| Wordpress | Wordpress | 2.6.1 | — |
| Wordpress | Wordpress | 2.6.2 | — |
| Wordpress | Wordpress | 2.6.3 | — |
| Wordpress | Wordpress | 2.7 | Coltrane |
| Wordpress | Wordpress | 2.7.1 | — |
| Wordpress | Wordpress | 2.8 | — |
| Wordpress | Wordpress | 2.8.1 | — |
| Wordpress | Wordpress | 2.8.2 | — |
References
- http://core.trac.wordpress.org/changeset/11768Exploit, Vendor Advisory
- http://core.trac.wordpress.org/changeset/11769Exploit, Vendor Advisory
- http://wordpress.org/development/2009/08/wordpress-2-8-3-security-release/Patch, Vendor Advisory
- http://www.debian.org/security/2009/dsa-1871Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/08/04/5Mailing List, Third Party Advisory
- http://core.trac.wordpress.org/changeset/11768Exploit, Vendor Advisory
- http://core.trac.wordpress.org/changeset/11769Exploit, Vendor Advisory
- http://wordpress.org/development/2009/08/wordpress-2-8-3-security-release/Patch, Vendor Advisory
- http://www.debian.org/security/2009/dsa-1871Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/08/04/5Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2853?
How severe is CVE-2009-2853?
How do I fix CVE-2009-2853?
Are you affected by CVE-2009-2853?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
