CVE-2005-2110: Medium severity WordPress vulnerability
Published Jul 1, 2005
·Updated
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.
Affected Software
7 affected components
WordPress=1.0.1
WordPress=1.0.2
WordPress=1.5.1.2
WordPress=1.2
WordPress=1.0
WordPress=1.5
WordPress=1.5.1
Remediation
Patch Available
Event History
Jul 1, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2110?
CVE-2005-2110 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2005-2110?
To fix CVE-2005-2110, upgrade WordPress to version 1.5.1.3 or later.
3
What systems are affected by CVE-2005-2110?
CVE-2005-2110 affects WordPress versions 1.0 to 1.5.1.2.
4
What type of vulnerability is CVE-2005-2110?
CVE-2005-2110 is an information disclosure vulnerability.
5
Can CVE-2005-2110 be exploited remotely?
Yes, CVE-2005-2110 can be exploited by remote attackers.