CVE-2007-0262

WordPress 2.0.6-2.1Alpha 3 - Info Disclosure

Title source: llm
STIX 2.1

Description

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/33458
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/456731/100/0/threaded

Scores

EPSS 0.0096
EPSS Percentile 76.8%

Details

Status published
Products (2)
wordpress/wordpress 2.0.6
wordpress/wordpress 2.1 alpha_3
Published Jan 16, 2007
Tracked Since Feb 18, 2026