Lucene search

K
cveMitreCVE-2009-2853
HistoryAug 18, 2009 - 9:00 p.m.

CVE-2009-2853

2009-08-1821:00:00
CWE-264
mitre
web.nvd.nist.gov
53
cve-2009-2853
wordpress
2.8.3
privilege escalation
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.014

Percentile

86.4%

Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.

Affected configurations

Nvd
Node
wordpresswordpressMatch0.71
OR
wordpresswordpressMatch0.71beta
OR
wordpresswordpressMatch0.71beta_3
OR
wordpresswordpressMatch0.72
OR
wordpresswordpressMatch0.72beta_1
OR
wordpresswordpressMatch0.72beta_2
OR
wordpresswordpressMatch0.72rc1
OR
wordpresswordpressMatch0.711
OR
wordpresswordpressMatch1.0
OR
wordpresswordpressMatch1.0.1miles
OR
wordpresswordpressMatch1.0.1rc1
OR
wordpresswordpressMatch1.2
OR
wordpresswordpressMatch1.2beta
OR
wordpresswordpressMatch1.2rc1
OR
wordpresswordpressMatch1.2.1
OR
wordpresswordpressMatch1.2.2
OR
wordpresswordpressMatch1.5
OR
wordpresswordpressMatch1.5.1
OR
wordpresswordpressMatch1.5.1.3
OR
wordpresswordpressMatch1.5.2
OR
wordpresswordpressMatch2.0
OR
wordpresswordpressMatch2.0.1
OR
wordpresswordpressMatch2.0.2
OR
wordpresswordpressMatch2.0.3
OR
wordpresswordpressMatch2.0.4
OR
wordpresswordpressMatch2.0.5ronan
OR
wordpresswordpressMatch2.0.6
OR
wordpresswordpressMatch2.0.7
OR
wordpresswordpressMatch2.0.9
OR
wordpresswordpressMatch2.0.10
OR
wordpresswordpressMatch2.0.11
OR
wordpresswordpressMatch2.1ella
OR
wordpresswordpressMatch2.1.1
OR
wordpresswordpressMatch2.1.1dangerous
OR
wordpresswordpressMatch2.1.2
OR
wordpresswordpressMatch2.1.3
OR
wordpresswordpressMatch2.2
OR
wordpresswordpressMatch2.2.1
OR
wordpresswordpressMatch2.2.2
OR
wordpresswordpressMatch2.2.3
OR
wordpresswordpressMatch2.3
OR
wordpresswordpressMatch2.3beta3
OR
wordpresswordpressMatch2.3rc1
OR
wordpresswordpressMatch2.3.1
OR
wordpresswordpressMatch2.3.1rc1
OR
wordpresswordpressMatch2.3.2
OR
wordpresswordpressMatch2.5
OR
wordpresswordpressMatch2.5.1
OR
wordpresswordpressMatch2.6
OR
wordpresswordpressMatch2.6.1
OR
wordpresswordpressMatch2.6.2
OR
wordpresswordpressMatch2.6.3
OR
wordpresswordpressMatch2.7coltrane
OR
wordpresswordpressMatch2.7.1
OR
wordpresswordpressMatch2.8
OR
wordpresswordpressMatch2.8.1
OR
wordpresswordpressMatch2.8.2
VendorProductVersionCPE
wordpresswordpress0.71cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:*
wordpresswordpress0.71cpe:2.3:a:wordpress:wordpress:0.71:beta:*:*:*:*:*:*
wordpresswordpress0.71cpe:2.3:a:wordpress:wordpress:0.71:beta_3:*:*:*:*:*:*
wordpresswordpress0.72cpe:2.3:a:wordpress:wordpress:0.72:*:*:*:*:*:*:*
wordpresswordpress0.72cpe:2.3:a:wordpress:wordpress:0.72:beta_1:*:*:*:*:*:*
wordpresswordpress0.72cpe:2.3:a:wordpress:wordpress:0.72:beta_2:*:*:*:*:*:*
wordpresswordpress0.72cpe:2.3:a:wordpress:wordpress:0.72:rc1:*:*:*:*:*:*
wordpresswordpress0.711cpe:2.3:a:wordpress:wordpress:0.711:*:*:*:*:*:*:*
wordpresswordpress1.0cpe:2.3:a:wordpress:wordpress:1.0:*:*:*:*:*:*:*
wordpresswordpress1.0.1cpe:2.3:a:wordpress:wordpress:1.0.1:miles:*:*:*:*:*:*
Rows per page:
1-10 of 571

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.014

Percentile

86.4%