1
Candidate: CVE-2009-2334
4
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2334
6
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not
7
require administrative authentication to access the configuration of a
8
plugin, which allows remote attackers to specify a configuration file in
9
the page parameter to obtain sensitive information or modify this file, as
10
demonstrated by the (1) collapsing-archives/options.txt, (2)
11
akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4)
12
wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files.
13
NOTE: this can be leveraged for cross-site scripting (XSS) and denial of
23
upstream_wordpress: released (2.8.1)
24
dapper_wordpress: ignored (reached end-of-life)
25
hardy_wordpress: ignored (reached end-of-life)
26
intrepid_wordpress: needs-triage (reached end-of-life)
27
jaunty_wordpress: ignored (reached end-of-life)
28
karmic_wordpress: not-affected (2.8.3-2ubuntu1)
29
lucid_wordpress: not-affected (2.8.3-2ubuntu1)
30
maverick_wordpress: not-affected (2.8.3-2ubuntu1)
31
natty_wordpress: not-affected (2.8.3-2ubuntu1)
32
oneiric_wordpress: not-affected (2.8.3-2ubuntu1)
33
devel_wordpress: not-affected (2.8.3-2ubuntu1)