Back to search
CVE-2006-3390
Published: Jul 6, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1187
third-party-advisory
x_refsource_SREASON
20928
third-party-advisory
x_refsource_SECUNIA
21447
third-party-advisory
x_refsource_SECUNIA
18779
vdb-entry
x_refsource_BID
20060704 Re: WordPress 2.0.3 SQL Error and Full Path Disclosure
mailing-list
x_refsource_BUGTRAQ
GLSA-200608-19
vendor-advisory
x_refsource_GENTOO
ADV-2006-2661
vdb-entry
x_refsource_VUPEN
20060702 WordPress 2.0.3 SQL Error and Full Path Disclosure
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now