CVE-2009-2431: Input Validation
Published Jul 10, 2009
·Updated
WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.
Affected Software
1 affected component
WordPress=2.7.1
Remediation
Patch Available
Patch Available
Event History
Jul 10, 2009
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2431?
The severity of CVE-2009-2431 is classified as moderate due to exposure of sensitive information.
2
How do I fix CVE-2009-2431?
To fix CVE-2009-2431, upgrade to a newer version of WordPress that does not expose the author's username in HTML comments.
3
Which versions of WordPress are affected by CVE-2009-2431?
CVE-2009-2431 specifically affects WordPress version 2.7.1.
4
What type of vulnerability is CVE-2009-2431?
CVE-2009-2431 is an information disclosure vulnerability that allows attackers to read sensitive information from the HTML source.
5
Can CVE-2009-2431 be exploited remotely?
Yes, CVE-2009-2431 can be exploited remotely by attackers to obtain sensitive information.