CVE-2008-0195Sensitive Information Exposure in Wordpress

Severity
5.0MEDIUMNVD
EPSS
2.4%
top 14.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 10
Latest updateMay 1

Description

WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/wordpress< wordpress 2.1.0-1 (bookworm)
Debianwordpress/wordpress< 2.1.0-1+3

🔴Vulnerability Details

2
GHSA
GHSA-mc4g-fgwx-48vc: WordPress 22022-05-01
OSV
CVE-2008-0195: WordPress 22008-01-10

📋Vendor Advisories

1
Debian
CVE-2008-0195: wordpress - WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive informa...2008
CVE-2008-0195 — Sensitive Information Exposure | cvebase