CVE Database
/

CVE-2008-0508

Back to search

CVE-2008-0508

Published: Jan 31, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows remote attackers to modify the oldstructure (aka dean_pm_config[oldstructure]) configuration setting as administrators via the old_struct parameter in a deans_permalinks_migration.php action to wp-admin/options-general.php, as demonstrated by placing an XSS sequence in this setting.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2008-0281
vdb-entry
x_refsource_VUPEN
28593
third-party-advisory
x_refsource_SECUNIA
3595
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now