CVE-2007-1244
Publication date 3 March 2007
Last updated 24 July 2024
Ubuntu priority
Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.
Status
Package | Ubuntu Release | Status |
---|---|---|
wordpress | 9.10 karmic |
Not affected
|
9.04 jaunty |
Not affected
|
|
8.10 intrepid |
Not affected
|
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy |
Not affected
|
|
7.04 feisty |
Not affected
|
|
6.10 edgy | Ignored end of life, was needed | |
6.06 LTS dapper | Ignored end of life |