Vulnerabilities > CVE-2005-2612 - Remote Security vulnerability in WordPress
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Exploit-Db
description | WordPress cache_lastpostdate Arbitrary Code Execution. CVE-2005-2612. Webapps exploit for php platform |
id | EDB-ID:16895 |
last seen | 2016-02-02 |
modified | 2010-07-03 |
published | 2010-07-03 |
reporter | metasploit |
source | https://www.exploit-db.com/download/16895/ |
title | WordPress cache_lastpostdate - Arbitrary Code Execution |
Metasploit
description | This module exploits an arbitrary PHP code execution flaw in the WordPress blogging software. This vulnerability is only present when the PHP 'register_globals' option is enabled (common for hosting providers). All versions of WordPress prior to 1.5.1.3 are affected. |
id | MSF:EXPLOIT/UNIX/WEBAPP/WP_LASTPOST_EXEC |
last seen | 2020-06-01 |
modified | 2017-07-24 |
published | 2015-03-23 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2612 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/unix/webapp/wp_lastpost_exec.rb |
title | WordPress cache_lastpostdate Arbitrary Code Execution |
Nessus
NASL family | CGI abuses |
NASL id | WORDPRESS_CACHE_LASTPOSTDATE_CODE_INJECTION.NASL |
description | The installed version of WordPress on the remote host will accept and execute arbitrary PHP code passed to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19414 |
published | 2005-08-11 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19414 |
title | WordPress Cookie 'cache_lastpostdate' Parameter PHP Code Injection |
code |
|
Packetstorm
data source https://packetstormsecurity.com/files/download/131000/wp_lastpost_exec.rb.txt id PACKETSTORM:131000 last seen 2016-12-05 published 2015-03-24 reporter H D Moore source https://packetstormsecurity.com/files/131000/WordPress-cache_lastpostdate-Arbitrary-Code-Execution.html title WordPress cache_lastpostdate Arbitrary Code Execution data source https://packetstormsecurity.com/files/download/82365/php_wordpress_lastpost.rb.txt id PACKETSTORM:82365 last seen 2016-12-05 published 2009-10-30 reporter str0ke source https://packetstormsecurity.com/files/82365/WordPress-cache_lastpostdate-Arbitrary-Code-Execution.html title WordPress cache_lastpostdate Arbitrary Code Execution