[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Thu, 20 Nov 2008 21:14:15 -0500 (EST)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: wordpress can be subject of delayed
attacks via cookies
======================================================
Name: CVE-2008-5113
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5113
Reference: MLIST:[oss-security] 20081113 CVE request: wordpress can be subject of delayed attacks via cookies
Reference: URL:http://openwall.com/lists/oss-security/2008/11/14/1
Reference: CONFIRM:http://bugs.debian.org/504771
WordPress 2.6.3 relies on the REQUEST superglobal array in certain
dangerous situations, which makes it easier for remote attackers to
conduct delayed and persistent cross-site request forgery (CSRF)
attacks via crafted cookies, as demonstrated by attacks that (1)
delete user accounts or (2) cause a denial of service (loss of
application access). NOTE: this issue relies on the presence of an
independent vulnerability that allows cookie injection.
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ