CVE-2009-2853
published 2009-08-18CVE-2009-2853: Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3)…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.71%
90.8th percentile
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.8.3-1 (bookworm) | wordpress 2.8.3-1 (bookworm) |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2009-2853: wordpress - Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct r...
vendor_debian·2009·CVSS 10.0
CVE-2009-2853 [CRITICAL] CVE-2009-2853: wordpress - Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct r...
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
Scope: local
bookworm: resolved (fixed in 2.8.3-1)
bullseye: resolved (fixed in 2.8.3-1)
forky: resolved (fixed in 2.8.3-1)
sid: resolved (fixed in 2.8.3-1)
trixie: resolved (fixed in 2.8.3-1)
GHSA
GHSA-gpxx-3842-mjw3: Wordpress before 2
ghsa_unreviewed·2022-05-02
CVE-2009-2853 [HIGH] GHSA-gpxx-3842-mjw3: Wordpress before 2
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
OSV
CVE-2009-2853: Wordpress before 2
osv·2009-08-18·CVSS 10.0
CVE-2009-2853 [CRITICAL] CVE-2009-2853: Wordpress before 2
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://core.trac.wordpress.org/changeset/11768http://core.trac.wordpress.org/changeset/11769http://wordpress.org/development/2009/08/wordpress-2-8-3-security-release/http://www.debian.org/security/2009/dsa-1871http://www.openwall.com/lists/oss-security/2009/08/04/5http://core.trac.wordpress.org/changeset/11768http://core.trac.wordpress.org/changeset/11769http://wordpress.org/development/2009/08/wordpress-2-8-3-security-release/http://www.debian.org/security/2009/dsa-1871http://www.openwall.com/lists/oss-security/2009/08/04/5
2009-08-18
Published