CVE-2005-2110
published 2005-07-05CVE-2005-2110: WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed…
PriorityP413medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.88%
85.3th percentile
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 1.5.1.3-1 (bookworm) | wordpress 1.5.1.3-1 (bookworm) |
| debian | wordpress | < wordpress 2.0.2-1 (bookworm) | wordpress 2.0.2-1 (bookworm) |
| debian | wordpress | < wordpress 2.0.5-0.1 (bookworm) | wordpress 2.0.5-0.1 (bookworm) |
| debian | wordpress | < wordpress 1.5.2-1 (bookworm) | wordpress 1.5.2-1 (bookworm) |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 2.0.5-0.1 | 2.0.5-0.1 |
| wordpress | wordpress | >= 0 < 1.5.2-1 | 1.5.2-1 |
| wordpress | wordpress | >= 0 < 2.0.2-1 | 2.0.2-1 |
| wordpress | wordpress | >= 0 < 1.5.1.3-1 | 1.5.1.3-1 |
| wordpress | wordpress | >= 0 < 2.0.5-0.1 | 2.0.5-0.1 |
| wordpress | wordpress | >= 0 < 1.5.2-1 | 1.5.2-1 |
| wordpress | wordpress | >= 0 < 2.0.2-1 | 2.0.2-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vwrg-2mrv-m4gf: WordPress 1
ghsa_unreviewed·2022-05-01
CVE-2005-2110 [MEDIUM] GHSA-vwrg-2mrv-m4gf: WordPress 1
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.
GHSA
GHSA-9mm4-3grj-7cx7: WordPress before 1
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2005-4463 [MEDIUM] GHSA-9mm4-3grj-7cx7: WordPress before 1
WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error message related to undefined functions or failed includes. NOTE: the wp-admin/menu-header.php vector is already covered by CVE-2005-2110. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors were also reported to affect WordPress 2.0.1.
GHSA
GHSA-x3q2-3pwv-684v: WordPress 2
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-4743 [MEDIUM] GHSA-x3q2-3pwv-684v: WordPress 2
WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) header.php, (13) hello.php, (14) wp-content/themes/default/index.php, (15) links.php, (16) livejournal.php, (17) mt.php, (18) page.php, (19) rss.php, (20) searchform.php, (21) search.php, (22) sidebar.php, (23) single.php, (24) textpattern.php, (25) upgrade-functions.php, (26) upgrade-schema.php, or (27) wp-db-backup.php, which reveal the path in various error messages. NOTE: another researcher has disputed the details of this report, stating that version 2.0.5 does not exist. NOT
GHSA
GHSA-6vgm-3w54-5w82: WordPress 2
ghsa_unreviewed·2022-05-01·CVSS 5.3
CVE-2006-0986 [MEDIUM] GHSA-6vgm-3w54-5w82: WordPress 2
WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php, (11) admin-footer.php, and (12) menu.php in the wp-admin directory; and possibly (13) list directory contents of the wp-includes directory. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors are already covered by CVE-2005-4463. The menu-header.php vector is already covered by CVE-2005-2110. Other vectors might be covered by CVE-2005-1688. NOTE: if the typical installation of WordPress does not l
OSV
CVE-2006-4743: WordPress 2
osv·2006-09-13·CVSS 5.0
CVE-2006-4743 [MEDIUM] CVE-2006-4743: WordPress 2
WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) header.php, (13) hello.php, (14) wp-content/themes/default/index.php, (15) links.php, (16) livejournal.php, (17) mt.php, (18) page.php, (19) rss.php, (20) searchform.php, (21) search.php, (22) sidebar.php, (23) single.php, (24) textpattern.php, (25) upgrade-functions.php, (26) upgrade-schema.php, or (27) wp-db-backup.php, which reveal the path in various error messages. NOTE: another researcher has disputed the details of this report, stating that version 2.0.5 does not exist. NOT
OSV
CVE-2006-0986: WordPress 2
osv·2006-03-03·CVSS 5.3
CVE-2006-0986 [MEDIUM] CVE-2006-0986: WordPress 2
WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php, (11) admin-footer.php, and (12) menu.php in the wp-admin directory; and possibly (13) list directory contents of the wp-includes directory. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors are already covered by CVE-2005-4463. The menu-header.php vector is already covered by CVE-2005-2110. Other vectors might be covered by CVE-2005-1688. NOTE: if the typical installation of WordPress does not l
OSV
CVE-2005-4463: WordPress before 1
osv·2005-12-21·CVSS 5.0
CVE-2005-4463 [MEDIUM] CVE-2005-4463: WordPress before 1
WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error message related to undefined functions or failed includes. NOTE: the wp-admin/menu-header.php vector is already covered by CVE-2005-2110. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors were also reported to affect WordPress 2.0.1.
OSV
CVE-2005-2110: WordPress 1
osv·2005-07-05·CVSS 5.0
CVE-2005-2110 [MEDIUM] CVE-2005-2110: WordPress 1
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.
Debian
CVE-2006-0986: wordpress - WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive informat...
vendor_debian·2006·CVSS 5.3
CVE-2006-0986 [MEDIUM] CVE-2006-0986: wordpress - WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive informat...
WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php, (11) admin-footer.php, and (12) menu.php in the wp-admin directory; and possibly (13) list directory contents of the wp-includes directory. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors are already covered by CVE-2005-4463. The menu-header.php vector is already covered by CVE-2005-2110. Other vectors might be covered by CVE-2005-1688. NOTE: if the typical installation of WordPress does not l
Debian
CVE-2006-4743: wordpress - WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive inform...
vendor_debian·2006·CVSS 5.0
CVE-2006-4743 [MEDIUM] CVE-2006-4743: wordpress - WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive inform...
WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup.php, (9) dotclear.php, (10) footer.php, (11) functions.php, (12) header.php, (13) hello.php, (14) wp-content/themes/default/index.php, (15) links.php, (16) livejournal.php, (17) mt.php, (18) page.php, (19) rss.php, (20) searchform.php, (21) search.php, (22) sidebar.php, (23) single.php, (24) textpattern.php, (25) upgrade-functions.php, (26) upgrade-schema.php, or (27) wp-db-backup.php, which reveal the path in various error messages. NOTE: another researcher has disputed the details of this report, stating that version 2.0.5 does not exist. NOT
Debian
CVE-2005-2110: wordpress - WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive inform...
vendor_debian·2005·CVSS 5.0
CVE-2005-2110 [MEDIUM] CVE-2005-2110: wordpress - WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive inform...
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.
Scope: local
bookworm: resolved (fixed in 1.5.1.3-1)
bullseye: resolved (fixed in 1.5.1.3-1)
forky: resolved (fixed in 1.5.1.3-1)
sid: resolved (fixed in 1.5.1.3-1)
trixie: resolved (fixed in 1.5.1.3-1)
Debian
CVE-2005-4463: wordpress - WordPress before 1.5.2 allows remote attackers to obtain sensitive information v...
vendor_debian·2005·CVSS 5.0
CVE-2005-4463 [MEDIUM] CVE-2005-4463: wordpress - WordPress before 1.5.2 allows remote attackers to obtain sensitive information v...
WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error message related to undefined functions or failed includes. NOTE: the wp-admin/menu-header.php vector is already covered by CVE-2005-2110. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors were also reported to affect WordPress 2.0.1.
Scope: local
bookworm: resolved (fixed in 1.5.2-1)
bullseye: resolved (fixed in 1.5.2-1)
forky: resolved (fixed in 1.5.2-1)
sid: resolved (fixed in 1.5.2-1)
trixie: resolved (fixed in 1.5.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://NeoSecurityTeam.net/advisories/Advisory-17.txthttp://marc.info/?l=bugtraq&m=112006967221438&w=2http://secunia.com/advisories/15831http://www.gulftech.org/?node=research&article_id=00085-06282005http://www.securityfocus.com/archive/1/426304/100/0/threadedhttp://NeoSecurityTeam.net/advisories/Advisory-17.txthttp://marc.info/?l=bugtraq&m=112006967221438&w=2http://secunia.com/advisories/15831http://www.gulftech.org/?node=research&article_id=00085-06282005http://www.securityfocus.com/archive/1/426304/100/0/threaded
2005-07-05
Published