CVE-2007-3639
published 2007-07-10CVE-2007-3639: WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer…
PriorityP416medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.39%
82.1th percentile
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.2.2-1 (bookworm) | wordpress 2.2.2-1 (bookworm) |
| wordpress | wordpress | <= 2.2.1 | — |
| wordpress | wordpress | >= 0 < 2.2.2-1 | 2.2.2-1 |
| wordpress | wordpress | >= 0 < 2.2.2-1 | 2.2.2-1 |
| wordpress | wordpress | >= 0 < 2.2.2-1 | 2.2.2-1 |
| wordpress | wordpress | >= 0 < 2.2.2-1 | 2.2.2-1 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f3vf-85qq-vx9q: WordPress before 2
ghsa_unreviewed·2022-05-01
CVE-2007-3639 [MEDIUM] GHSA-f3vf-85qq-vx9q: WordPress before 2
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.
OSV
CVE-2007-3639: WordPress before 2
osv·2007-07-10·CVSS 4.0
CVE-2007-3639 [MEDIUM] CVE-2007-3639: WordPress before 2
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.
Debian
CVE-2007-3639: wordpress - WordPress before 2.2.2 allows remote attackers to redirect visitors to other web...
vendor_debian·2007·CVSS 4.0
CVE-2007-3639 [MEDIUM] CVE-2007-3639: wordpress - WordPress before 2.2.2 allows remote attackers to redirect visitors to other web...
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.
Scope: local
bookworm: resolved (fixed in 2.2.2-1)
bullseye: resolved (fixed in 2.2.2-1)
forky: resolved (fixed in 2.2.2-1)
sid: resolved (fixed in 2.2.2-1)
trixie: resolved (fixed in 2.2.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/40802http://secunia.com/advisories/30013http://securityreason.com/securityalert/2869http://www.debian.org/security/2008/dsa-1564http://www.securityfocus.com/archive/1/472885/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/35272http://osvdb.org/40802http://secunia.com/advisories/30013http://securityreason.com/securityalert/2869http://www.debian.org/security/2008/dsa-1564http://www.securityfocus.com/archive/1/472885/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/35272
2007-07-10
Published