CVE-2008-0191: Infoleak
Published Jan 10, 2008
·Updated
WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.
Affected Software
2 affected components
WordPress=2.2
WordPress=2.3
Event History
Jan 10, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0191?
CVE-2008-0191 is classified as a moderate severity vulnerability.
2
How does CVE-2008-0191 impact WordPress users?
CVE-2008-0191 allows remote attackers to obtain sensitive information such as full path details and SQL database structure.
3
Which versions of WordPress are affected by CVE-2008-0191?
CVE-2008-0191 affects WordPress versions 2.2.x and 2.3.x.
4
How do I fix CVE-2008-0191?
To fix CVE-2008-0191, it is recommended to upgrade to a WordPress version later than 2.3.
5
Can CVE-2008-0191 lead to further exploits?
Yes, the information disclosed by CVE-2008-0191 can potentially be used by attackers to exploit other vulnerabilities.