CVE-2008-1930
published 2008-04-28CVE-2008-1930: The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.00%
91.3th percentile
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.5.1-1 (bookworm) | wordpress 2.5.1-1 (bookworm) |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 2.5.1-1 | 2.5.1-1 |
| wordpress | wordpress | >= 0 < 2.5.1-1 | 2.5.1-1 |
| wordpress | wordpress | >= 0 < 2.5.1-1 | 2.5.1-1 |
| wordpress | wordpress | >= 0 < 2.5.1-1 | 2.5.1-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wordpress: security fixes in upstream version 2.5.1 (CVE-2008-1930, CVE-2008-2068)
vendor_redhat·2008-04-25·CVSS 7.5
CVE-2008-2068 [HIGH] wordpress: security fixes in upstream version 2.5.1 (CVE-2008-1930, CVE-2008-2068)
wordpress: security fixes in upstream version 2.5.1 (CVE-2008-1930, CVE-2008-2068)
Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Debian
CVE-2008-1930: wordpress - The cookie authentication method in WordPress 2.5 relies on a hash of a concaten...
vendor_debian·2008·CVSS 9.8
CVE-2008-1930 [CRITICAL] CVE-2008-1930: wordpress - The cookie authentication method in WordPress 2.5 relies on a hash of a concaten...
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.
Scope: local
bookworm: resolved (fixed in 2.5.1-1)
bullseye: resolved (fixed in 2.5.1-1)
forky: resolved (fixed in 2.5.1-1)
sid: resolved (fixed in 2.5.1-1)
trixie: resolved (fixed in 2.5.1-1)
GHSA
GHSA-m86r-5c2c-w6rq: The cookie authentication method in WordPress 2
ghsa_unreviewed·2022-05-01·CVSS 9.8
CVE-2008-1930 [CRITICAL] CWE-287 GHSA-m86r-5c2c-w6rq: The cookie authentication method in WordPress 2
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.
OSV
CVE-2008-1930: The cookie authentication method in WordPress 2
osv·2008-04-28·CVSS 9.8
CVE-2008-1930 [CRITICAL] CVE-2008-1930: The cookie authentication method in WordPress 2
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.
No detection rules found.
No public exploits indexed.
Bugzilla
wordpress: security fixes in upstream version 2.5.1 (CVE-2008-1930, CVE-2008-2068)
bugzilla·2008-04-28·CVSS 7.5
CVE-2008-1930 [HIGH] wordpress: security fixes in upstream version 2.5.1 (CVE-2008-1930, CVE-2008-2068)
wordpress: security fixes in upstream version 2.5.1 (CVE-2008-1930, CVE-2008-2068)
New upstream WordPress version 2.5.1 was released:
http://wordpress.org/development/2008/04/wordpress-251/
"... It includes a number of bug fixes, performance enhancements, and one
very important security fix. We recommend everyone update immediately,
particularly if your blog has open registration. The vulnerability is not
public but it will be shortly."
Release announcement suggests multiple security issues were fixed in this version:
"Many thanks to Steven Murdoch for responsibly reporting the security issue
(CVE-2008-1930) and Alex Concha for reporting an XSS issue."
Discussion:
CVE-2008-1930:
An attacker, who is able to register a specially crafted username on
a Wordpress 2.5 installation, is ab
Bugzilla
CVE-2007-6013 wordpress cookie authentication vulnerability
bugzilla·2007-11-20·CVSS 9.8
CVE-2007-6013 [CRITICAL] CVE-2007-6013 wordpress cookie authentication vulnerability
CVE-2007-6013 wordpress cookie authentication vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6013 to the following vulnerability:
Wordpress 1.5 to 2.3.1 uses cookie values based on the MD5 hash of a
password MD5 hash, which allows attackers to bypass authentication by
obtaining the MD5 hash from the user database, then generating the
authentication cookie from that hash.
References:
http://www.cl.cam.ac.uk/~sjm217/advisories/wordpress-cookie-auth.txt
http://www.securityfocus.com/archive/1/archive/1/483927/100/0/threaded
According to the advisory, there are multiple flaws in the way wordpress
handles authentication cookies (e.g. stolen cookie can be reused until password
is changed, cookie is not generated per login session, ...), so stealing
passwor
http://secunia.com/advisories/29965http://wordpress.org/development/2008/04/wordpress-251/http://www.cl.cam.ac.uk/users/sjm217/advisories/wordpress-cookie-integrity.txthttp://www.securityfocus.com/archive/1/491356/100/0/threadedhttp://www.securityfocus.com/bid/28935http://www.securitytracker.com/id?1019923http://www.vupen.com/english/advisories/2008/1372/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42027http://secunia.com/advisories/29965http://wordpress.org/development/2008/04/wordpress-251/http://www.cl.cam.ac.uk/users/sjm217/advisories/wordpress-cookie-integrity.txthttp://www.securityfocus.com/archive/1/491356/100/0/threadedhttp://www.securityfocus.com/bid/28935http://www.securitytracker.com/id?1019923http://www.vupen.com/english/advisories/2008/1372/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42027
2008-04-28
Published