CVE-2008-5695
EPSS 12.0%
描述
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to active_plugins.
如何修補 CVE-2008-5695
要修補 CVE-2008-5695,請將受影響套件升級到下列已修補版本。
- Debian/wordpress—升級至 2.3.2 或更新版本
CVE-2008-5695 正在被利用嗎?
中等 — EPSS 為 12.0%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 2.3.2