CVE-2007-0262: High severity WordPress vulnerability
WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0262?
CVE-2007-0262 is classified as a medium severity vulnerability due to potential exposure of sensitive information.
How do I fix CVE-2007-0262?
To fix CVE-2007-0262, upgrade to a patched version of WordPress that addresses this vulnerability.
What versions of WordPress are affected by CVE-2007-0262?
CVE-2007-0262 affects WordPress versions 2.0.6 and 2.1 Alpha 3.
What kind of information can be exposed by CVE-2007-0262?
CVE-2007-0262 allows attackers to obtain sensitive information, including file paths and certain SQL data.
What type of attack does CVE-2007-0262 facilitate?
CVE-2007-0262 facilitates a remote information disclosure attack by exploiting improper validation of a parameter.