|
|
| |
|
| |
wordpress: remote admin password reset
| Package(s): | wordpress |
CVE #(s): | |
| Created: | August 12, 2009 |
Updated: | August 12, 2009 |
| Description: |
From the advisory on full-disclosure:
A web browser is sufficient to reproduce this Proof of concept:
http://DOMAIN_NAME.TLD/wp-login.php?action=rp&key[]=
The password will be reset without any confirmation.
An attacker could exploit this vulnerability to compromise the admin account
of any wordpress/wordpress-mu <= 2.8.3
|
| Alerts: |
|
( Log in to post comments)
|
|
|