WordPress <= 1.5.1 - Multiple Vulnerabilities

wordpress

Software
WordPress
Versions
<= 1.5.1
Disclosure date
2005-12-21
CVE
CVE-2005-4463
References
Credits
Classification
Multiple Vulnerabilities
OWASP Top 10

Are your websites subject to this vulnerability?

Details

Because of these vulnerabilities, the attackers can obtain sensitive information via a direct request to wp-admin/upgrade-functions.php, wp-includes/vars.php, wp-admin/edit-form.php, wp-content/plugins/hello.php, wp-settings.php or wp-admin/edit-form-comment.php.

Solution

Update the WordPress to the latest available version (at least 1.5.2).

Found a vulnerability that puts your sites at risk?

Found a vulnerability? Help us secure the web and join our community of ethical hackers.

Are you the developer of this software? Hire our researchers for a thorough security audit.