FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-2762

This CVE name corresponds to:

Entered Topic
2009-08-12 wordpress -- remote admin password reset vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-2762
Phase Assigned(20090813)

Description

wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.

References

Source Reference
FULLDISC 20090810 WordPress <= 2.8.3 Remote admin reset password
MILW0RM 9410
MISC http://core.trac.wordpress.org/changeset/11798
CONFIRM http://wordpress.org/development/2009/08/2-8-4-security-release/
BID 36014
SECTRACK 1022707
SECUNIA 36237
XF wordpress-wplogin-security-bypass(52382)