Lucene search

K
patchstackSteven J. MurdochPATCHSTACK:28EAAD76D30BE9AB8D182ECA13E2A8CF
HistoryApr 23, 2008 - 12:00 a.m.

WordPress <= 2.5 - Cookie Integrity Protection Vulnerability

2008-04-2300:00:00
Steven J. Murdoch
patchstack.com
15

EPSS

0.012

Percentile

85.5%

The attackers can forge cookies by registering a username that results in the same concatenated string, because the cookie authentication method relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME.

Solution

           Update WordPress to version 2.5.1.

EPSS

0.012

Percentile

85.5%

Related for PATCHSTACK:28EAAD76D30BE9AB8D182ECA13E2A8CF