Lucene search

K
cvelistMitreCVELIST:CVE-2008-1930
HistoryApr 28, 2008 - 6:21 p.m.

CVE-2008-1930

2008-04-2818:21:00
mitre
www.cve.org
7

AI Score

9.5

Confidence

High

EPSS

0.012

Percentile

85.7%

The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with โ€œadminโ€ to obtain administrator privileges, aka a โ€œcryptographic splicingโ€ issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.

AI Score

9.5

Confidence

High

EPSS

0.012

Percentile

85.7%