| Vulnerability Name: | CVE-2008-0508 (CCN-39845) | ||||||||
| Assigned: | 2008-01-22 | ||||||||
| Published: | 2008-01-22 | ||||||||
| Updated: | 2018-10-15 | ||||||||
| Summary: | Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the oldstructure (aka dean_pm_config[oldstructure]) configuration setting as administrators via the old_struct parameter in a deans_permalinks_migration.php action to wp-admin/options-general.php, as demonstrated by placing an XSS sequence in this setting. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:U/RC:UC)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:POC/RL:U/RC:UC)
| ||||||||
| Vulnerability Type: | CWE-352 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Tue Jan 22 2008 - 14:50:58 CST XSRF under Dean's Permalinks Migration 1.0 Source: MITRE Type: CNA CVE-2008-0508 Source: MISC Type: Patch http://g30rg3x.com/wp-files/dpm_11gx.zip Source: MISC Type: Exploit, Patch http://g30rg3x.com/xsrf-bajo-deans-permalinks-migration-10 Source: MISC Type: Exploit http://packetstorm.linuxsecurity.com/0801-advisories/deans-xsrf.txt Source: CCN Type: SA28593 WordPress Permalinks Migration Plugin Cross-Site Request Forgery Source: SECUNIA Type: Vendor Advisory 28593 Source: SREASON Type: UNKNOWN 3595 Source: CCN Type: Dean Lee Web page Permalinks Migration Plugin for wordpress Source: CCN Type: OSVDB ID: 40643 Permalinks Migration WordPress Plugin dean_pm_config[oldstructure] Parameter CSRF Source: BUGTRAQ Type: UNKNOWN 20080122 XSRF under Deanâ??s Permalinks Migration 1.0 Source: VUPEN Type: UNKNOWN ADV-2008-0281 Source: XF Type: UNKNOWN permalinks-deanpmconfig-csrf(39845) Source: XF Type: UNKNOWN permalinks-deanpmconfig-csrf(39845) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||