CVE-2008-1930
WordPress Core < 2.5.1 - Authentication Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.
El método de autenticación por Cookie en WordPress 2.5 confía en un hash de la cadena que resulta de concatenar USERNAME y EXPIRY_TIME, lo que permite a atacantes remotos falsificar cookies registrando nombres de usuario que resulten en la misma cadena concatenada, como se demostró registrando nombres de usuario que comenzaban con "admin" para conseguir privilegios de administrador, también conocido como asunto "empalme criptográfico". NOTA: Esta vulnerabilidad existe debido a un parche incompleto para la vulnerabilidad CVE-2007-6013
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-04-23 CVE Reserved
- 2008-04-25 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
- CWE-288: Authentication Bypass Using an Alternate Path or Channel
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/29965 | Third Party Advisory | |
http://www.cl.cam.ac.uk/users/sjm217/advisories/wordpress-cookie-integrity.txt | X_refsource_misc | |
http://www.securityfocus.com/archive/1/491356/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1019923 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1372/references | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42027 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://wordpress.org/development/2008/04/wordpress-251 | 2018-10-11 | |
http://www.securityfocus.com/bid/28935 | 2018-10-11 |
URL | Date | SRC |
---|