Vulnerability Name: | CVE-2006-0986 (CCN-24957) | ||||||||
Assigned: | 2006-02-27 | ||||||||
Published: | 2006-02-27 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php, (11) admin-footer.php, and (12) menu.php in the wp-admin directory; and possibly (13) list directory contents of the wp-includes directory. Note: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors are already covered by CVE-2005-4463. The menu-header.php vector is already covered by CVE-2005-2110. Other vectors might be covered by CVE-2005-1688. Note: if the typical installation of WordPress does not list any site-specific files to wp-includes, then vector [13] is not an exposure. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Feb 27 2006 - 17:30:57 CST WordPress 2.0.1 Multiple Vulnerabilities Source: MITRE Type: CNA CVE-2006-0985 Source: MITRE Type: CNA CVE-2006-0986 Source: MISC Type: Exploit, Patch, Vendor Advisory http://NeoSecurityTeam.net/advisories/Advisory-17.txt Source: CCN Type: SA19050 WordPress Cross-Site Scripting Vulnerabilities Source: SECUNIA Type: UNKNOWN 19050 Source: CCN Type: WordPress Web site WordPress Source: CCN Type: OSVDB ID: 23557 WordPress wp-comments-post.php Multiple Field XSS Source: CCN Type: OSVDB ID: 23559 WordPress wp-admin/ Multiple Script Direct Request Path Disclosure Source: CCN Type: OSVDB ID: 23560 WordPress wp-includes/ Multiple Script Direct Request Path Disclosure Source: CCN Type: OSVDB ID: 59246 WordPress Multiple Script Direct Request Path Disclosure Source: BUGTRAQ Type: UNKNOWN 20060227 WordPress 2.0.1 Multiple Vulnerabilities Source: BUGTRAQ Type: UNKNOWN 20060228 FW: WordPress 2.0.1 Multiple Vulnerabilities Source: BUGTRAQ Type: UNKNOWN 20060302 Re: FW: WordPress 2.0.1 Multiple Vulnerabilities Source: CCN Type: BID-16880 WordPress Multiple HTML Injection Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-0777 Source: XF Type: UNKNOWN wordpress-wpcommentspost-xss(24957) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |