Vulnerabilities > CVE-2006-4028 - Remote Security vulnerability in WordPress
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an unspecified issue related to "Anyone can register" functionality (user registration for guests).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200608-19.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200608-19 (WordPress: Privilege escalation) The WordPress developers have confirmed a vulnerability in capability checking for plugins. Impact : By exploiting a flaw, a user can circumvent WordPress access restrictions when using plugins. The actual impact depends on the configuration of WordPress and may range from trivial to critical, possibly even the execution of arbitrary PHP code. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22218 |
published | 2006-08-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22218 |
title | GLSA-200608-19 : WordPress: Privilege escalation |
code |
|
References
- http://bugs.gentoo.org/show_bug.cgi?id=142142
- http://secunia.com/advisories/21309
- http://secunia.com/advisories/21447
- http://security.gentoo.org/glsa/glsa-200608-19.xml
- http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/
- http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/
- http://wordpress.org/development/2006/07/wordpress-204/
- http://www.osvdb.org/27633
- http://www.securityfocus.com/bid/19247
- http://www.vupen.com/english/advisories/2006/3071