CVE-2007-6013
published 2007-11-19CVE-2007-6013: Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the…
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.28%
87.0th percentile
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.5.1-1 (bookworm) | wordpress 2.5.1-1 (bookworm) |
| debian | wordpress | < wordpress 2.5.0-1 (bookworm) | wordpress 2.5.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 2.5.0-1 | 2.5.0-1 |
| wordpress | wordpress | >= 0 < 2.5.1-1 | 2.5.1-1 |
| wordpress | wordpress | >= 0 < 2.5.0-1 | 2.5.0-1 |
| wordpress | wordpress | >= 0 < 2.5.1-1 | 2.5.1-1 |
| wordpress | wordpress | >= 0 < 2.5.0-1 | 2.5.0-1 |
| wordpress | wordpress | >= 0 < 2.5.1-1 | 2.5.1-1 |
| wordpress | wordpress | >= 0 < 2.5.0-1 | 2.5.0-1 |
| wordpress | wordpress | >= 0 < 2.5.1-1 | 2.5.1-1 |
| wordpress | wordpress | 1.5 – 2.3.1 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5g78-mv2p-rh9c: Wordpress 1
ghsa_unreviewed·2022-05-01
CVE-2007-6013 [MEDIUM] CWE-287 GHSA-5g78-mv2p-rh9c: Wordpress 1
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
GHSA
GHSA-m86r-5c2c-w6rq: The cookie authentication method in WordPress 2
ghsa_unreviewed·2022-05-01·CVSS 9.8
CVE-2008-1930 [CRITICAL] CWE-287 GHSA-m86r-5c2c-w6rq: The cookie authentication method in WordPress 2
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.
OSV
CVE-2008-1930: The cookie authentication method in WordPress 2
osv·2008-04-28·CVSS 9.8
CVE-2008-1930 [CRITICAL] CVE-2008-1930: The cookie authentication method in WordPress 2
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.
OSV
CVE-2007-6013: Wordpress 1
osv·2007-11-19·CVSS 9.8
CVE-2007-6013 [CRITICAL] CVE-2007-6013: Wordpress 1
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Debian
CVE-2008-1930: wordpress - The cookie authentication method in WordPress 2.5 relies on a hash of a concaten...
vendor_debian·2008·CVSS 9.8
CVE-2008-1930 [CRITICAL] CVE-2008-1930: wordpress - The cookie authentication method in WordPress 2.5 relies on a hash of a concaten...
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.
Scope: local
bookworm: resolved (fixed in 2.5.1-1)
bullseye: resolved (fixed in 2.5.1-1)
forky: resolved (fixed in 2.5.1-1)
sid: resolved (fixed in 2.5.1-1)
trixie: resolved (fixed in 2.5.1-1)
Red Hat
wordpress cookie authentication vulnerability
vendor_redhat·2007-11-19·CVSS 9.8
CVE-2007-6013 [CRITICAL] wordpress cookie authentication vulnerability
wordpress cookie authentication vulnerability
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Debian
CVE-2007-6013: wordpress - Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a passwo...
vendor_debian·2007·CVSS 9.8
CVE-2007-6013 [CRITICAL] CVE-2007-6013: wordpress - Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a passwo...
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Scope: local
bookworm: resolved (fixed in 2.5.0-1)
bullseye: resolved (fixed in 2.5.0-1)
forky: resolved (fixed in 2.5.0-1)
sid: resolved (fixed in 2.5.0-1)
trixie: resolved (fixed in 2.5.0-1)
No detection rules found.
No public exploits indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/058576.htmlhttp://osvdb.org/40801http://secunia.com/advisories/27714http://secunia.com/advisories/28310http://securityreason.com/securityalert/3375http://trac.wordpress.org/ticket/5367http://www.cl.cam.ac.uk/~sjm217/advisories/wordpress-cookie-auth.txthttp://www.securityfocus.com/archive/1/483927/100/0/threadedhttp://www.securitytracker.com/id?1018980http://www.vupen.com/english/advisories/2007/3941https://exchange.xforce.ibmcloud.com/vulnerabilities/38578https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00079.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00098.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2007-November/058576.htmlhttp://osvdb.org/40801http://secunia.com/advisories/27714http://secunia.com/advisories/28310http://securityreason.com/securityalert/3375http://trac.wordpress.org/ticket/5367http://www.cl.cam.ac.uk/~sjm217/advisories/wordpress-cookie-auth.txthttp://www.securityfocus.com/archive/1/483927/100/0/threadedhttp://www.securitytracker.com/id?1018980http://www.vupen.com/english/advisories/2007/3941https://exchange.xforce.ibmcloud.com/vulnerabilities/38578https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00079.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00098.html
2007-11-19
Published