Vulnerability Name: CVE-2009-2854 (CCN-52946) Assigned: 2009-08-03 Published: 2009-08-03 Updated: 2017-11-22 Summary: Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N )4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N )3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-264 Vulnerability Consequences: Bypass Security References: Source: CONFIRM Type: Vendor Advisoryhttp://core.trac.wordpress.org/changeset/11765 Source: CONFIRM Type: Vendor Advisoryhttp://core.trac.wordpress.org/changeset/11766 Source: MITRE Type: CNACVE-2009-2854 Source: CCN Type: WordPress Blog, August 3, 2009WordPress 2.8.3 Security Release Source: CONFIRM Type: Patch, Vendor Advisoryhttp://wordpress.org/development/2009/08/wordpress-2-8-3-security-release/ Source: DEBIAN Type: Third Party AdvisoryDSA-1871 Source: DEBIAN Type: DSA-1871wordpress -- several vulnerabilities Source: MLIST Type: Mailing List, Third Party Advisory[oss-security] 20090804 CVE request: Wordpress Source: XF Type: UNKNOWNwordpress-wpadmin-sec-bypass(52946) Vulnerable Configuration: Configuration 1 :cpe:/a:wordpress:wordpress:*:*:*:*:*:*:*:* (Version <= 2.8.2)Configuration CCN 1 :cpe:/a:wordpress:wordpress:0.7:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.2:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.3:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.5:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.6:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1.3:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.9:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.11:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3.2:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3.3:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.10:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.7:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1.3:rc2:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1.3:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.5:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:0.6.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:0.6.2.1:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:0.71:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.0:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.0.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.3.1:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.5:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.10:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.10:rc2:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.0.8:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:0.711:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.4:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.6:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.6:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.6.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.5::strayhorn:*:*:*:*:* OR cpe:/a:wordpress:wordpress:0.71::gold:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.0.1::miles:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.0.2::blakey:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.0::platinum:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.2::mingus:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2.0:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.2:beta:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:0.72:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:0.72:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.1:alpha_3:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:0.72:beta1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:0.72:beta2:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3.1:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.6.5:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.7.1:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.3:beta3:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.0:rc4:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.0:rc3:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.0:rc2:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.0:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:0.71-gold:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.6.3:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.8.1:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.8.2:*:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2::revision5002:*:*:*:*:* OR cpe:/a:wordpress:wordpress:1.2:delta:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.2::revision5003:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.8.1:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.8.1:beta1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.8:beta1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.8.1:beta2:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.8.1:jazzes_themes_and_widgets:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.7:-:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.7:beta1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.7:beta2:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.7:beta3:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.7:rc1:*:*:*:*:*:* OR cpe:/a:wordpress:wordpress:2.7:coltrane:*:*:*:*:*:* AND cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:* OR cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
wordpress wordpress *
wordpress wordpress 0.7
wordpress wordpress 1.2
wordpress wordpress 1.2.1
wordpress wordpress 1.5.1.2
wordpress wordpress 1.5.1.3
wordpress wordpress 1.5.2
wordpress wordpress 2.0.1
wordpress wordpress 2.0.2
wordpress wordpress 2.0.3
wordpress wordpress 2.0.5
wordpress wordpress 2.0.6
wordpress wordpress 2.1.1
wordpress wordpress 2.1.2
wordpress wordpress 2.1.3
wordpress wordpress 2.2
wordpress wordpress 2.2.1
wordpress wordpress 2.3
wordpress wordpress 2.0.9
wordpress wordpress 2.0.11
wordpress wordpress 2.3.2
wordpress wordpress 2.3.3
wordpress wordpress 2.3.1
wordpress wordpress 2.2.3
wordpress wordpress 2.2.2
wordpress wordpress 2.0.10
wordpress wordpress 2.0.7
wordpress wordpress 2.0.4
wordpress wordpress 2.0
wordpress wordpress 2.1.3 rc2
wordpress wordpress 2.1.3 rc1
wordpress wordpress 2.1
wordpress wordpress 2.5
wordpress wordpress 0.6.2
wordpress wordpress 0.6.2.1
wordpress wordpress 0.71
wordpress wordpress 1.0
wordpress wordpress 1.0.1
wordpress wordpress 1.0.2
wordpress wordpress 1.2.2
wordpress wordpress 1.3.1
wordpress wordpress 1.5
wordpress wordpress 1.5.1
wordpress wordpress 1.5.1.1
wordpress wordpress 2.0.10 rc1
wordpress wordpress 2.0.10 rc2
wordpress wordpress 2.0.8
wordpress wordpress 0.711
wordpress wordpress 1.4
wordpress wordpress 1.6
wordpress wordpress 2.5.1
wordpress wordpress 2.6
wordpress wordpress 2.6.1
wordpress wordpress 1.5
wordpress wordpress 0.71
wordpress wordpress 1.0.1
wordpress wordpress 1.0.2
wordpress wordpress 1.0
wordpress wordpress 1.2
wordpress wordpress 2.2.0
wordpress wordpress 1.2 beta
wordpress wordpress 0.72 rc1
wordpress wordpress 0.72
wordpress wordpress 2.1 alpha_3
wordpress wordpress 0.72 beta1
wordpress wordpress 0.72 beta2
wordpress wordpress 2.3.1 rc1
wordpress wordpress 2.6.5
wordpress wordpress 2.7.1
wordpress wordpress 2.3 rc1
wordpress wordpress 2.3 beta3
wordpress wordpress 1.0 rc4
wordpress wordpress 1.0 rc3
wordpress wordpress 1.0 rc2
wordpress wordpress 1.0 rc1
wordpress wordpress 0.71-gold
wordpress wordpress 2.6.3
wordpress wordpress 2.8.1
wordpress wordpress 2.8.2
wordpress wordpress 2.2
wordpress wordpress 1.2 delta
wordpress wordpress 2.2
wordpress wordpress 2.8.1 rc1
wordpress wordpress 2.8.1 beta1
wordpress wordpress 2.8 beta1
wordpress wordpress 2.8.1 beta2
wordpress wordpress 2.8.1 jazzes_themes_and_widgets
wordpress wordpress 2.7
wordpress wordpress 2.7 beta1
wordpress wordpress 2.7 beta2
wordpress wordpress 2.7 beta3
wordpress wordpress 2.7 rc1
wordpress wordpress 2.7 coltrane
debian debian linux 4.0
debian debian linux 5.0