CVE-2008-4769
Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 8.97% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- wordpress/wordpress
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29949Vendor Advisory
- http://trac.wordpress.org/changeset/7586
- http://www.debian.org/security/2009/dsa-1871
- http://www.juniper.fi/security/auto/vulnerabilities/vuln28845.html
- http://www.securityfocus.com/bid/28845Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41920
- http://secunia.com/advisories/29949Vendor Advisory
- http://trac.wordpress.org/changeset/7586
- http://www.debian.org/security/2009/dsa-1871
- http://www.juniper.fi/security/auto/vulnerabilities/vuln28845.html
- http://www.securityfocus.com/bid/28845Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41920
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.