Candidate: CVE-2008-5695 PublicDate: 2008-12-19 18:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5695 http://mu.wordpress.org/forums/topic.php?id=7534&page&replies=1 Description: wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to active_plugins. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_wordpress: upstream_wordpress: released (1.3.2 and 2.3.3) dapper_wordpress: ignored (reached end-of-life) gutsy_wordpress: needs-triage (reached end-of-life) hardy_wordpress: not-affected (2.3.3-1ubuntu1) intrepid_wordpress: not-affected (2.5.1-8ubuntu1) jaunty_wordpress: not-affected (2.5.1-11ubuntu1) karmic_wordpress: not-affected (2.5.1-11ubuntu1) devel_wordpress: not-affected (2.5.1-11ubuntu1)