Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1312
    posted: 11/18/08
  • NSM Daily Update #1312
    posted: 11/18/08
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1312
    posted: 11/18/08
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1300
    posted: 11/18/08
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 11/17/08

Title: WordPress 'get_edit_post_link()' & 'get_edit_comment_link()' Multiple Eavesdropping Vulnerabilities

Severity: MODERATE

Description:

WordPress is a web-based publishing application implemented in PHP.

WordPress is prone to multiple eavesdropping vulnerabilities because the 'get_edit_post_link()' and 'get_edit_comment_link()' functions fail to use SSL when transmitting data. The affected functions are being used for administrative purposes.

Successfully exploiting this issue will allow attackers to obtain sensitive information and possibly to impersonate users and tamper with network data.

Versions prior to WordPress 2.6.1 are vulnerable.

Affected Products:

  • WordPress WordPress 2.0.0
  • WordPress WordPress 2.0.1
  • WordPress WordPress 2.0.10
  • WordPress WordPress 2.0.10-RC1
  • WordPress WordPress 2.0.10-RC2
  • WordPress WordPress 2.0.11
  • WordPress WordPress 2.0.2
  • WordPress WordPress 2.0.3
  • WordPress WordPress 2.0.4
  • WordPress WordPress 2.0.5
  • WordPress WordPress 2.0.6
  • WordPress WordPress 2.0.7
  • WordPress WordPress 2.1
  • WordPress WordPress 2.1.1
  • WordPress WordPress 2.1.2
  • WordPress WordPress 2.1.3
  • WordPress WordPress 2.1.3
  • WordPress WordPress 2.1.3-RC1
  • WordPress WordPress 2.1.3-RC2
  • WordPress WordPress 2.2
  • WordPress WordPress 2.2 Revision 5002
  • WordPress WordPress 2.2 Revision 5003
  • WordPress WordPress 2.2.1
  • WordPress WordPress 2.2.1
  • WordPress WordPress 2.2.2
  • WordPress WordPress 2.2.3
  • WordPress WordPress 2.3
  • WordPress WordPress 2.3.1
  • WordPress WordPress 2.3.2
  • WordPress WordPress 2.3.3
  • WordPress WordPress 2.5
  • WordPress WordPress 2.5.1
  • WordPress WordPress 2.6
  • WordPress WordPress 2.6.1

References: