vendor:
WordPress
by:
str0ke, hdm
7.5
CVSS
HIGH
Arbitrary Code Execution
CWE
Product Name: WordPress
Affected Version From:
Affected Version To: 1.5.1.2
Patch Exists: YES
Related CWE: CVE-2005-2612
CPE:
Platforms Tested: php
2005
WordPress cache_lastpostdate Arbitrary Code Execution
This module exploits an arbitrary PHP code execution flaw in the WordPress blogging software. This vulnerability is only present when the PHP 'register_globals' option is enabled (common for hosting providers). All versions of WordPress prior to 1.5.1.3 are affected.
Mitigation:
Disable PHP 'register_globals' option, update to version 1.5.1.3 or later