Vulnerability Name:

CVE-2008-2146 (CCN-42379)

Assigned:2008-05-12
Published:2008-05-12
Updated:2017-08-08
Summary:wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.
CVSS v3 Severity:6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
4.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2008-2146

Source: OSVDB
Type: UNKNOWN
45188

Source: CCN
Type: WordPress Changeset 6029, 09/04/07 03:21:04
trunk/wp-includes/vars.php

Source: CONFIRM
Type: Exploit
http://trac.wordpress.org/changeset/6029

Source: CONFIRM
Type: Exploit
http://trac.wordpress.org/changeset?old_path=tags%2F2.2.2&old=6063&new_path=tags%2F2.2.3&new=6063#file10

Source: CCN
Type: WordPress Ticket #4748
Unprivileged users can perform some actions on pages they aren't allowed to access

Source: CONFIRM
Type: Patch
http://trac.wordpress.org/ticket/4748

Source: CCN
Type: WordPress Web site
WordPress › Blog Tool and Weblog Platform

Source: CCN
Type: OSVDB ID: 45188
WordPress wp-includes/vars.php PATH_INFO Access Restriction Bypass

Source: XF
Type: UNKNOWN
wordpress-vars-security-bypass(42379)

Source: XF
Type: UNKNOWN
wordpress-vars-security-bypass(42379)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:wordpress:wordpress:0.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.6.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.7:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.71:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.711:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.0:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.4:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5-strayhorn:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.6:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.3:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.5:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.6:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.7:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.8:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.9:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.10:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.10_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.10_rc2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.11:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.3:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.3_rc1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.3_rc2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:*:*:*:*:*:*:*:* (Version <= 2.2.2)
  • OR cpe:/a:wordpress:wordpress:2.2_revision5002:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2_revision5003:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:wordpress:wordpress:0.7:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.3:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.5:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.6:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.3:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.9:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.11:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.10:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.7:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.3:rc2:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1.3:rc1:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.6.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.71:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.0:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5-strayhorn:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.10:rc1:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.10:rc2:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:2.0.8:-:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:0.711:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.4:*:*:*:*:*:*:*
  • OR cpe:/a:wordpress:wordpress:1.6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    wordpress wordpress 0.6.2
    wordpress wordpress 0.6.2.1
    wordpress wordpress 0.7
    wordpress wordpress 0.71
    wordpress wordpress 0.711
    wordpress wordpress 1.0
    wordpress wordpress 1.0.1
    wordpress wordpress 1.0.2
    wordpress wordpress 1.2
    wordpress wordpress 1.2.1
    wordpress wordpress 1.2.2
    wordpress wordpress 1.3.1
    wordpress wordpress 1.4
    wordpress wordpress 1.5
    wordpress wordpress 1.5-strayhorn
    wordpress wordpress 1.5.1
    wordpress wordpress 1.5.1.1
    wordpress wordpress 1.5.1.2
    wordpress wordpress 1.5.1.3
    wordpress wordpress 1.5.2
    wordpress wordpress 1.6
    wordpress wordpress 2.0
    wordpress wordpress 2.0.1
    wordpress wordpress 2.0.2
    wordpress wordpress 2.0.3
    wordpress wordpress 2.0.4
    wordpress wordpress 2.0.5
    wordpress wordpress 2.0.6
    wordpress wordpress 2.0.7
    wordpress wordpress 2.0.8
    wordpress wordpress 2.0.9
    wordpress wordpress 2.0.10
    wordpress wordpress 2.0.10_rc1
    wordpress wordpress 2.0.10_rc2
    wordpress wordpress 2.0.11
    wordpress wordpress 2.1
    wordpress wordpress 2.1.1
    wordpress wordpress 2.1.2
    wordpress wordpress 2.1.3
    wordpress wordpress 2.1.3_rc1
    wordpress wordpress 2.1.3_rc2
    wordpress wordpress 2.2
    wordpress wordpress 2.2.0
    wordpress wordpress 2.2.1
    wordpress wordpress *
    wordpress wordpress 2.2_revision5002
    wordpress wordpress 2.2_revision5003
    wordpress wordpress 0.7
    wordpress wordpress 1.2
    wordpress wordpress 1.2.1
    wordpress wordpress 1.5.1.2
    wordpress wordpress 1.5.1.3
    wordpress wordpress 1.5.2
    wordpress wordpress 2.0.1
    wordpress wordpress 2.0.2
    wordpress wordpress 2.0.3
    wordpress wordpress 2.0.5
    wordpress wordpress 2.0.6
    wordpress wordpress 2.1.1
    wordpress wordpress 2.1.2
    wordpress wordpress 2.1.3
    wordpress wordpress 2.2
    wordpress wordpress 2.2.1
    wordpress wordpress 2.0.9
    wordpress wordpress 2.0.11
    wordpress wordpress 2.2.2
    wordpress wordpress 2.0.10
    wordpress wordpress 2.0.7
    wordpress wordpress 2.0.4
    wordpress wordpress 2.0
    wordpress wordpress 2.1.3 rc2
    wordpress wordpress 2.1.3 rc1
    wordpress wordpress 2.1
    wordpress wordpress 0.6.2
    wordpress wordpress 0.6.2.1
    wordpress wordpress 0.71
    wordpress wordpress 1.0
    wordpress wordpress 1.0.1
    wordpress wordpress 1.0.2
    wordpress wordpress 1.2.2
    wordpress wordpress 1.3.1
    wordpress wordpress 1.5
    wordpress wordpress 1.5-strayhorn
    wordpress wordpress 1.5.1
    wordpress wordpress 1.5.1.1
    wordpress wordpress 2.0.10 rc1
    wordpress wordpress 2.0.10 rc2
    wordpress wordpress 2.0.8
    wordpress wordpress 0.711
    wordpress wordpress 1.4
    wordpress wordpress 1.6