CVE-2008-2146
WordPress Core < 2.2.3 - Restriction Bypass
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.
El archivo wp-incluye/vars.php en Wordpress versiones anteriores a 2.2.3, no extrae apropiadamente la ruta (path) actual del PATH_INFO ($PHP_SELF), que permite a atacantes remotos omitir las restricciones de acceso previstas para ciertas páginas.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-09-08 CVE Published
- 2008-05-12 CVE Reserved
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
- CWE-284: Improper Access Control
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://osvdb.org/45188 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42379 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://trac.wordpress.org/changeset/6029 | 2024-08-07 | |
http://trac.wordpress.org/changeset?old_path=tags%2F2.2.2&old=6063&new_path=tags%2F2.2.3&new=6063#file10 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://trac.wordpress.org/ticket/4748 | 2017-08-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | <= 2.2.2 Search vendor "Wordpress" for product "Wordpress" and version " <= 2.2.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 0.6.2 Search vendor "Wordpress" for product "Wordpress" and version "0.6.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 0.6.2.1 Search vendor "Wordpress" for product "Wordpress" and version "0.6.2.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 0.7 Search vendor "Wordpress" for product "Wordpress" and version "0.7" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 0.71 Search vendor "Wordpress" for product "Wordpress" and version "0.71" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 0.711 Search vendor "Wordpress" for product "Wordpress" and version "0.711" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.0 Search vendor "Wordpress" for product "Wordpress" and version "1.0" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.0.1 Search vendor "Wordpress" for product "Wordpress" and version "1.0.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.0.2 Search vendor "Wordpress" for product "Wordpress" and version "1.0.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.2 Search vendor "Wordpress" for product "Wordpress" and version "1.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.2.1 Search vendor "Wordpress" for product "Wordpress" and version "1.2.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.2.2 Search vendor "Wordpress" for product "Wordpress" and version "1.2.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.3.1 Search vendor "Wordpress" for product "Wordpress" and version "1.3.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.4 Search vendor "Wordpress" for product "Wordpress" and version "1.4" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5 Search vendor "Wordpress" for product "Wordpress" and version "1.5" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5-strayhorn Search vendor "Wordpress" for product "Wordpress" and version "1.5-strayhorn" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5.1 Search vendor "Wordpress" for product "Wordpress" and version "1.5.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5.1.1 Search vendor "Wordpress" for product "Wordpress" and version "1.5.1.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5.1.2 Search vendor "Wordpress" for product "Wordpress" and version "1.5.1.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5.1.3 Search vendor "Wordpress" for product "Wordpress" and version "1.5.1.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5.2 Search vendor "Wordpress" for product "Wordpress" and version "1.5.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.6 Search vendor "Wordpress" for product "Wordpress" and version "1.6" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0 Search vendor "Wordpress" for product "Wordpress" and version "2.0" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.1 Search vendor "Wordpress" for product "Wordpress" and version "2.0.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.2 Search vendor "Wordpress" for product "Wordpress" and version "2.0.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.3 Search vendor "Wordpress" for product "Wordpress" and version "2.0.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.4 Search vendor "Wordpress" for product "Wordpress" and version "2.0.4" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.5 Search vendor "Wordpress" for product "Wordpress" and version "2.0.5" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.6 Search vendor "Wordpress" for product "Wordpress" and version "2.0.6" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.7 Search vendor "Wordpress" for product "Wordpress" and version "2.0.7" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.8 Search vendor "Wordpress" for product "Wordpress" and version "2.0.8" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.9 Search vendor "Wordpress" for product "Wordpress" and version "2.0.9" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.10 Search vendor "Wordpress" for product "Wordpress" and version "2.0.10" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.10_rc1 Search vendor "Wordpress" for product "Wordpress" and version "2.0.10_rc1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.10_rc2 Search vendor "Wordpress" for product "Wordpress" and version "2.0.10_rc2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.11 Search vendor "Wordpress" for product "Wordpress" and version "2.0.11" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.1 Search vendor "Wordpress" for product "Wordpress" and version "2.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.1.1 Search vendor "Wordpress" for product "Wordpress" and version "2.1.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.1.2 Search vendor "Wordpress" for product "Wordpress" and version "2.1.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.1.3 Search vendor "Wordpress" for product "Wordpress" and version "2.1.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.1.3_rc1 Search vendor "Wordpress" for product "Wordpress" and version "2.1.3_rc1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.1.3_rc2 Search vendor "Wordpress" for product "Wordpress" and version "2.1.3_rc2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.2 Search vendor "Wordpress" for product "Wordpress" and version "2.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.2.0 Search vendor "Wordpress" for product "Wordpress" and version "2.2.0" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.2.1 Search vendor "Wordpress" for product "Wordpress" and version "2.2.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.2_revision5002 Search vendor "Wordpress" for product "Wordpress" and version "2.2_revision5002" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.2_revision5003 Search vendor "Wordpress" for product "Wordpress" and version "2.2_revision5003" | - |
Affected
|