First published: Mon Oct 27 2014(Updated: )
PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | =0.70 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1599 is considered a critical vulnerability due to the potential for arbitrary code execution by remote attackers.
To fix CVE-2003-1599, upgrade to a newer version of WordPress, as version 0.70 is vulnerable.
CVE-2003-1599 specifically affects WordPress version 0.70.
CVE-2003-1599 exploits the $abspath variable in the wp-links/links.all.php file, allowing attackers to include remote PHP files.
Websites running WordPress version 0.70 are at risk from CVE-2003-1599 if not patched.