CVE-2008-2146: High severity wordpress vulnerability
wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATHINFO ($PHPSELF), which allows remote attackers to bypass intended access restrictions for certain pages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2146?
CVE-2008-2146 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive pages.
How do I fix CVE-2008-2146?
To fix CVE-2008-2146, you should upgrade your WordPress installation to version 2.2.3 or later.
What versions of WordPress are affected by CVE-2008-2146?
CVE-2008-2146 affects WordPress versions up to 2.2.2, including all versions from 0.6 to 2.2.2.
Can CVE-2008-2146 be exploited remotely?
Yes, CVE-2008-2146 can be exploited remotely, allowing attackers to bypass access restrictions on affected WordPress installations.
What are the potential impacts of CVE-2008-2146?
The potential impacts of CVE-2008-2146 include unauthorized access to restricted areas of a WordPress site, leading to data exposure or further attacks.