LWN.net Logo

wordpress: privilege escalation

Package(s):wordpress CVE #(s):CVE-2008-3747
Created:September 5, 2008 Updated:September 12, 2008
Description: The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.
Alerts:
Fedora FEDORA-2008-7279 2008-09-05
Fedora FEDORA-2008-7463 2008-09-05

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds