CVE-2008-0508
Dean's Permalinks Migration <= 1.0 - Cross-Site Request Forgery to Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the oldstructure (aka dean_pm_config[oldstructure]) configuration setting as administrators via the old_struct parameter in a deans_permalinks_migration.php action to wp-admin/options-general.php, as demonstrated by placing an XSS sequence in this setting.
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en deans_permalinks_migration.php en el plugin Dean's Permalinks Migration 1.0 para WordPress, permite a atacantes remotos modificar la configuración de oldstructure (también conocido como dean_pm_config[oldstructure]) como administradores a través del parámetro old_struct en una acción deans_permalinks_migration.php a wp-admin/options-general.php, como se demostró poniendo una secuencia XSS en este ajuste de la configuración.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-01-21 CVE Published
- 2008-01-31 CVE Reserved
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-10-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/3595 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/486840/100/0/threaded | Mailing List | |
http://www.vupen.com/english/advisories/2008/0281 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39845 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://g30rg3x.com/xsrf-bajo-deans-permalinks-migration-10 | 2024-08-07 | |
http://packetstorm.linuxsecurity.com/0801-advisories/deans-xsrf.txt | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://g30rg3x.com/wp-files/dpm_11gx.zip | 2018-10-15 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/28593 | 2018-10-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Search vendor "Wordpress" | Permalinks Migration Plugin Search vendor "Wordpress" for product "Permalinks Migration Plugin" | 1.0 Search vendor "Wordpress" for product "Permalinks Migration Plugin" and version "1.0" | - |
Affected
|