CVE Database
/

CVE-2008-1930

Back to search

CVE-2008-1930

Published: Apr 28, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.

VendorProductVersions

n/a

n/a

affected
n/a

References

28935
vdb-entry
x_refsource_BID
ADV-2008-1372
vdb-entry
x_refsource_VUPEN
1019923
vdb-entry
x_refsource_SECTRACK
29965
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now