4438Third-party advisory
http://securityreason.com/securityalert/4438 CVE-2008-4616
WordPress Plugin SpamBam - Key Calculation Security Bypass
Record summary
CVE-2008-4616 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a shared key.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin SpamBam - Key Calculation Security BypassExploitDB exploitby RomeroNot analyzed1 file
References
520080115 Exploiting the SpamBam plugin for wordpressmailing list
http://www.securityfocus.com/archive/1/486333/100/200/threaded 27291vdb entry
http://www.securityfocus.com/bid/27291 spambam-client-security-bypass(39690)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39690 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-4616