CVE Database
/

CVE-2007-3639

Back to search

CVE-2007-3639

Published: Jul 10, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

2869
third-party-advisory
x_refsource_SREASON
30013
third-party-advisory
x_refsource_SECUNIA
40802
vdb-entry
x_refsource_OSVDB
DSA-1564
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now