Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CVE-2008-5695

EPSS 16.37% · P95

Public Exploits 1

ExploitDB · 1 EDB-5066 [webapps]
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-5695

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to active_plugins.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
WordPress 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress MU 1.3.2之前的版本和WordPress 2.3.2 及其早期版本的wp-admin/options.php存在输入验证错误漏洞,该漏洞源于没有适当地验证对更新选项的请求,这会允许具有管理选项和上传文件能力的远程验证用户通过上传一个PHP脚本并添加该脚本的路径名到active_plugins中,以执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-5695

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-5695

登录查看更多情报信息。

Vendor Advisories for CVE-2008-5695 (2)

Exploits & Public PoCs for CVE-2008-5695 (1)

Other References for CVE-2008-5695 (4)

Same Patch Batch · n/a · 2008-12-19 · 26 CVEs total

CVE-2008-5684Sun Solaris 'libICE' 未明 拒绝服务漏洞
CVE-2008-5683Opera Web 浏览器信息泄露漏洞
CVE-2008-5682Opera Web浏览器XSLT内嵌模板跨站攻击漏洞
CVE-2008-5681Opera Web浏览器9.63版本修复多个安全漏洞
CVE-2008-5680Opera Web 缓冲区溢出漏洞
CVE-2008-5679Opera Web Browser HTML Parsing 堆远程代码执行漏洞
CVE-2008-5691Phonecian Casina FlashAX Active控件缓冲区溢出漏洞
CVE-2008-5690Sun Solaris Kerberos本地拒绝服务漏洞
CVE-2008-5689Sun Solaris IP隧道参数空指针引用漏洞
CVE-2008-5688Mediawiki debugging敏感信息泄露漏洞
CVE-2008-5687mediawiki 权限许可和访问控制漏洞
CVE-2008-5686IBM Tivoli Provisioning Manager SOAP命令绕过认证漏洞
CVE-2008-5685Sun Fire Servers IP Spoofing 安全绕过漏洞
CVE-2008-5692Ipswitch WS_FTP Server Manager 权限绕过漏洞
CVE-2008-5252mediawiki 跨站请求伪造漏洞
CVE-2008-5250MediaWiki Wiki页跨站攻击漏洞
CVE-2008-5249MediaWiki 跨站脚本攻击河多个 HTML 注入漏洞
CVE-2008-5086libvirt Local 安全绕过漏洞
CVE-2008-5078GNU Enscript src/psgen.c栈溢出漏洞
CVE-2008-4122Joomla 会话设置cookie泄露漏洞

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-5695

No comments yet


Leave a comment