Vulnerability Name: CVE-2009-2336 (CCN-51619) Assigned: 2009-07-08 Published: 2009-07-08 Updated: 2018-11-08 Summary: The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. Note : the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience." CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): NoneAvailibility (A): None
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
Vulnerability Type: CWE-16 Vulnerability Consequences: Obtain Information References: Source: CCN Type: CORE-2009-0515WordPress Privileges Unchecked in admin.php and Multiple Information Disclosures Source: MISC Type: Exploit, Patch, Third Party Advisoryhttp://corelabs.coresecurity.com/index.php?action=view&type=advisory&name=WordPress_Privileges_Unchecked Source: MITRE Type: CNACVE-2009-2336 Source: CCN Type: SECTRACK ID: 1022528WordPress Bugs Permit Cross-Site Scripting and Information Disclosure Attacks Source: SECTRACK Type: Patch, Third Party Advisory, VDB Entry1022528 Source: CCN Type: WordPress Web siteWordPress Source: EXPLOIT-DB Type: Third Party Advisory, VDB Entry9110 Source: OSVDB Type: Broken Link, Patch55714 Source: CCN Type: OSVDB ID: 55714WordPress Forgotten Mail Interface New Password Request User Enumeration Source: BUGTRAQ Type: Third Party Advisory, VDB Entry20090708 CORE-2009-01515 - WordPress Privileges Unchecked in admin.php and Multiple Information Source: BID Type: Third Party Advisory, VDB Entry35581 Source: CCN Type: BID-35581WordPress Multiple Existing/Non-Existing Username Enumeration Weaknesses Source: VUPEN Type: Patch, Third Party AdvisoryADV-2009-1833 Source: XF Type: UNKNOWNwordpress-forgottenmail-info-disclosure(51619) Source: FEDORA Type: Third Party AdvisoryFEDORA-2009-8529 Source: FEDORA Type: Third Party AdvisoryFEDORA-2009-8538 Source: FEDORA Type: Third Party AdvisoryFEDORA-2009-7701 Source: FEDORA Type: Third Party AdvisoryFEDORA-2009-7729 Vulnerable Configuration: Configuration 1 :cpe:/a:wordpress:wordpress:*:*:*:*:*:*:*:* (Version < 2.8.1)OR cpe:/a:wordpress:wordpress_mu:*:*:*:*:*:*:*:* (Version < 2.8.1) Configuration CCN 1 :cpe:/a:wordpress:wordpress:2.0.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.3:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.5:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.6:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1.3:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.9:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.11:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3.2:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3.3:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.10:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.7:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1.3:rc2:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1.3:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.5:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.10:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.10:rc2:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.8:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.6:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.6.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.6.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2.0:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1:alpha_3:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3.1:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress_mu:2.6:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress_mu:2.7:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.6.5:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress_mu:2.7.1:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
wordpress wordpress *
wordpress wordpress mu *
wordpress wordpress 2.0.1
wordpress wordpress 2.0.2
wordpress wordpress 2.0.3
wordpress wordpress 2.0.5
wordpress wordpress 2.0.6
wordpress wordpress 2.1.1
wordpress wordpress 2.1.2
wordpress wordpress 2.1.3
wordpress wordpress 2.2
wordpress wordpress 2.2.1
wordpress wordpress 2.3
wordpress wordpress 2.0.9
wordpress wordpress 2.0.11
wordpress wordpress 2.3.2
wordpress wordpress 2.3.3
wordpress wordpress 2.3.1
wordpress wordpress 2.2.3
wordpress wordpress 2.2.2
wordpress wordpress 2.0.10
wordpress wordpress 2.0.7
wordpress wordpress 2.0.4
wordpress wordpress 2.1.3 rc2
wordpress wordpress 2.1.3 rc1
wordpress wordpress 2.1
wordpress wordpress 2.5
wordpress wordpress 2.0.10 rc1
wordpress wordpress 2.0.10 rc2
wordpress wordpress 2.0.8
wordpress wordpress 2.5.1
wordpress wordpress 2.6
wordpress wordpress 2.6.1
wordpress wordpress 2.6.2
wordpress wordpress 2.2.0
wordpress wordpress 2.1 alpha_3
wordpress wordpress 2.3.1 rc1
wordpress wordpress mu 2.6
wordpress wordpress mu 2.7
wordpress wordpress 2.6.5
wordpress wordpress mu 2.7.1