| Title | WordPress における重要な情報を取得される脆弱性 |
|---|---|
| Summary | WordPress には、アップロードディレクトリへの書き込みアクセスを禁止している場合、重要な情報を取得される脆弱性が存在します。 |
| Possible impacts | 第三者により、XMLHttpRequest エラーメッセージ内の絶対パスを公開する不正なアップロードリクエストを介して、重要な情報を取得される可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | June 21, 2013, midnight |
| Registration Date | July 9, 2013, 6:52 p.m. |
| Last Update | Aug. 19, 2013, 6:02 p.m. |
| CVSS2.0 : 警告 | |
| Score | 4.3 |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
| WordPress.org |
| WordPress 3.5.2 未満 |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2013年07月09日] 掲載 [2013年08月19日] ベンダ情報:Debian (DSA-2718) を追加 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message. |
|---|---|
| Publication Date | July 9, 2013, 5:55 a.m. |
| Registration Date | Jan. 26, 2021, 3:38 p.m. |
| Last Update | Nov. 21, 2024, 10:51 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:wordpress:wordpress:2.8.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.2.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:3.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.3.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.8.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.6.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:3.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.2.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.8.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.1.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.3.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:3.3.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.2.5:a:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.7.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.6.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.8.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.8.4:a:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.6.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.3.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.8.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.2.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.6.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.3.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:3.3.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.6.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | 3.5.1 | ||||
| cpe:2.3:a:wordpress:wordpress:1.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.8.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.9.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:3.3.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.9.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:3.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.8.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:3.4.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:3.4.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.2.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.9.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.3.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:1.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.8.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.0.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:wordpress:wordpress:2.3:*:*:*:*:*:*:* | |||||