CVE-2008-5113
published 2008-11-17CVE-2008-5113: WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and…
PriorityP412medium4CVSS 2.0
AVNACHAuNCNIPAP
EPSS
1.33%
67.9th percentile
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.5.1-10 (bookworm) | wordpress 2.5.1-10 (bookworm) |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 2.5.1-10 | 2.5.1-10 |
| wordpress | wordpress | >= 0 < 2.5.1-10 | 2.5.1-10 |
| wordpress | wordpress | >= 0 < 2.5.1-10 | 2.5.1-10 |
| wordpress | wordpress | >= 0 < 2.5.1-10 | 2.5.1-10 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:N/I:P/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m5gr-m2fc-vhr6: WordPress 2
ghsa_unreviewed·2022-05-17
CVE-2008-5113 [MEDIUM] CWE-352 GHSA-m5gr-m2fc-vhr6: WordPress 2
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.
OSV
CVE-2008-5113: WordPress 2
osv·2008-11-17·CVSS 4.0
CVE-2008-5113 [MEDIUM] CVE-2008-5113: WordPress 2
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.
Red Hat
wordpress delayed attack via cookies
vendor_redhat·2008-11-06·CVSS 4.0
CVE-2008-5113 [MEDIUM] wordpress delayed attack via cookies
wordpress delayed attack via cookies
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.
Debian
CVE-2008-5113: wordpress - WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous sit...
vendor_debian·2008·CVSS 4.0
CVE-2008-5113 [MEDIUM] CVE-2008-5113: wordpress - WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous sit...
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.
Scope: local
bookworm: resolved (fixed in 2.5.1-10)
bullseye: resolved (fixed in 2.5.1-10)
forky: resolved (fixed in 2.5.1-10)
sid: resolved (fixed in 2.5.1-10)
trixie: resolved (fixed in 2.5.1-10)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-5113 wordpress delayed attack via cookies [Fdevel]
bugzilla·2008-11-18·CVSS 4.0
CVE-2008-5113 [MEDIUM] CVE-2008-5113 wordpress delayed attack via cookies [Fdevel]
CVE-2008-5113 wordpress delayed attack via cookies [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora 10 development cycle.
Changing version to '10'.
More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping
---
This message is a reminder that Fedora 10 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 10. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora
'vers
Bugzilla
CVE-2008-5113 wordpress delayed attack via cookies
bugzilla·2008-11-18·CVSS 4.0
CVE-2008-5113 [MEDIUM] CVE-2008-5113 wordpress delayed attack via cookies
CVE-2008-5113 wordpress delayed attack via cookies
WordPress 2.6.3 relies on the REQUEST superglobal array in certain
dangerous situations, which makes it easier for remote attackers to
conduct delayed and persistent cross-site request forgery (CSRF)
attacks via crafted cookies, as demonstrated by attacks that (1)
delete user accounts or (2) cause a denial of service (loss of
application access). NOTE: this issue relies on the presence of an
independent vulnerability that allows cookie injection.
http://openwall.com/lists/oss-security/2008/11/14/1
http://bugs.debian.org/504771
Discussion:
Created wordpress tracking bugs for this issue
CVE-2008-5113 Affects: F8 [bug #471990]
CVE-2008-5113 Affects: F9 [bug #471991]
CVE-2008-5113 Affects: Fdevel [bug #471992]
---
2.6.5 is available whi
Bugzilla
CVE-2008-5113 wordpress delayed attack via cookies [F9]
bugzilla·2008-11-18·CVSS 4.0
CVE-2008-5113 [MEDIUM] CVE-2008-5113 wordpress delayed attack via cookies [F9]
CVE-2008-5113 wordpress delayed attack via cookies [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=471991,
---
This message is a reminder that Fedora 9 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 9. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora
'version' of '9'.
Package Maintainer: If you wish for this bug to
Bugzilla
CVE-2008-5113 wordpress delayed attack via cookies [F8]
bugzilla·2008-11-18·CVSS 4.0
CVE-2008-5113 [MEDIUM] CVE-2008-5113 wordpress delayed attack via cookies [F8]
CVE-2008-5113 wordpress delayed attack via cookies [F8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%208&bugs=471990,
---
This message is a reminder that Fedora 8 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 8. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora
'version' of '8'.
Package Maintainer: If you wish for this bug to
http://bugs.debian.org/504771http://openwall.com/lists/oss-security/2008/11/14/1http://www.debian.org/security/2009/dsa-1871https://exchange.xforce.ibmcloud.com/vulnerabilities/46698http://bugs.debian.org/504771http://openwall.com/lists/oss-security/2008/11/14/1http://www.debian.org/security/2009/dsa-1871https://exchange.xforce.ibmcloud.com/vulnerabilities/46698
2008-11-17
Published