CVE-2005-4463

Publication date 21 December 2005

Last updated 24 July 2024


Ubuntu priority

WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error message related to undefined functions or failed includes. NOTE: the wp-admin/menu-header.php vector is already covered by CVE-2005-2110. NOTE: the vars.php, edit-form.php, wp-settings.php, and edit-form-comment.php vectors were also reported to affect WordPress 2.0.1.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
wordpress 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected