CVE-2005-1688

Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:57

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=111661517716733&w=2 - Third Party Advisory () http://marc.info/?l=bugtraq&m=111661517716733&w=2 - Third Party Advisory

28 Dec 2023, 19:27

Type Values Removed Values Added
References (BUGTRAQ) http://marc.info/?l=bugtraq&m=111661517716733&w=2 - (BUGTRAQ) http://marc.info/?l=bugtraq&m=111661517716733&w=2 - Third Party Advisory
CWE NVD-CWE-Other CWE-425

Information

Published : 2005-05-20 04:00

Updated : 2024-11-20 23:57


NVD link : CVE-2005-1688

Mitre link : CVE-2005-1688

CVE.ORG link : CVE-2005-1688


JSON object : View

Products Affected

wordpress

  • wordpress
CWE
CWE-425

Direct Request ('Forced Browsing')