CVE-2005-1688: Medium severity WordPress vulnerability
Published May 20, 2005
·Updated
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.
Affected Software
1 affected component
WordPress<=1.5
Event History
May 20, 2005
CVE Published
04:00 AM
May 25, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1688?
CVE-2005-1688 is considered to have a medium severity due to the potential for information disclosure.
2
How do I fix CVE-2005-1688?
Upgrading to WordPress version 1.5.1 or later mitigates the risk associated with CVE-2005-1688.
3
What type of information can be disclosed by CVE-2005-1688?
CVE-2005-1688 allows for the disclosure of file paths through error messages triggered by direct requests to specific WordPress directories.
4
Which versions of WordPress are affected by CVE-2005-1688?
CVE-2005-1688 affects all versions of WordPress up to and including 1.5.
5
What are the impacted directories related to CVE-2005-1688?
The impacted directories for CVE-2005-1688 include wp-content/themes/, wp-includes/, and wp-admin/.