|
|
Log in / Subscribe / Register

wordpress: cross-site request forgery vulnerability

Package(s):wordpress CVE #(s):CVE-2008-5113
Created:August 27, 2009 Updated:September 2, 2009
Description: From the National Vulnerability Database entry: "WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection."
Alerts:
Debian DSA-1871-2 wordpress 2009-08-27

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds