Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 277377

Summary: <www-apps/wordpress-2.8.1: wp-admin/admin.php multiple vulnerabilities (CVE-2009-2334)
Product: Gentoo Security Reporter: Stefan Behte (RETIRED) <craig>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: trivial CC: web-apps
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://wordpress.org/development/2009/07/wordpress-2-8-1/
Whiteboard: ~3 [ebuild]
Package list:
Runtime testing required: ---

Description Stefan Behte (RETIRED) gentoo-dev Security 2009-07-10 23:22:33 UTC
CVE-2009-2334 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2334):
  wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does
  not require administrative authentication to access the configuration
  of a plugin, which allows remote attackers to specify a configuration
  file in the page parameter to obtain sensitive information or modify
  this file, as demonstrated by the (1)
  collapsing-archives/options.txt, (2) akismet/readme.txt, (3)
  related-ways-to-take-action/options.php, (4)
  wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php
  files. NOTE: this can be leveraged for cross-site scripting (XSS) and
  denial of service.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2009-07-10 23:23:51 UTC
Whoops.

*** This bug has been marked as a duplicate of bug 277317 ***