CVE-2008-0196
Publication date 10 January 2008
Last updated 24 July 2024
Ubuntu priority
Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the page parameter to certain PHP scripts under wp-admin/ or (2) the import parameter to wp-admin/admin.php, as demonstrated by discovering the full path via a request for the \..\..\wp-config pathname; and allow remote attackers to modify arbitrary files via a .. (dot dot) in the file parameter to wp-admin/templates.php.
Status
Package | Ubuntu Release | Status |
---|---|---|
wordpress | 9.10 karmic |
Not affected
|
9.04 jaunty |
Not affected
|
|
8.10 intrepid |
Not affected
|
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy |
Not affected
|
|
7.04 feisty |
Not affected
|
|
6.10 edgy | Ignored end of life, was needed | |
6.06 LTS dapper | Ignored end of life |