CVE-2009-2854
Publication date 18 August 2009
Last updated 24 July 2024
Ubuntu priority
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.
Status
Package | Ubuntu Release | Status |
---|---|---|
wordpress | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Not affected
|
|
10.04 LTS lucid |
Not affected
|
|
9.10 karmic |
Not affected
|
|
9.04 jaunty | Ignored end of life | |
8.10 intrepid | Ignored end of life, was needs-triage | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life |