Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-3385

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2012-3385
Last Modified 23 Jul 2012 03:03:10
Published 22 Jul 2012 01:55:03
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-3385

Summary

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

Vulnerable Systems

Application

  • Wordpress 0.71

  • Wordpress 1.0

  • Wordpress 1.0.1

  • Wordpress 1.0.2

  • Wordpress 1.1.1

  • Wordpress 1.2

  • Wordpress 1.2.1

  • Wordpress 1.2.2

  • Wordpress 1.2.3

  • Wordpress 1.2.4

  • Wordpress 1.2.5

  • Wordpress 1.3

  • Wordpress 1.3.2

  • Wordpress 1.3.3

  • Wordpress 1.5

  • Wordpress 1.5.1

  • Wordpress 1.5.1.1

  • Wordpress 1.5.1.2

  • Wordpress 1.5.1.3

  • Wordpress 1.5.2

  • Wordpress 2.0

  • Wordpress 2.0.1

  • Wordpress 2.0.10

  • Wordpress 2.0.11

  • Wordpress 2.0.2

  • Wordpress 2.0.4

  • Wordpress 2.0.5

  • Wordpress 2.0.6

  • Wordpress 2.0.7

  • Wordpress 2.0.8

  • Wordpress 2.0.9

  • Wordpress 2.1

  • Wordpress 2.1.1

  • Wordpress 2.1.2

  • Wordpress 2.1.3

  • Wordpress 2.2

  • Wordpress 2.2.1

  • Wordpress 2.2.2

  • Wordpress 2.2.3

  • Wordpress 2.3

  • Wordpress 2.3.1

  • Wordpress 2.3.2

  • Wordpress 2.3.3

  • Wordpress 2.5

  • Wordpress 2.5.1

  • Wordpress 2.6

  • Wordpress 2.6.1

  • Wordpress 2.6.2

  • Wordpress 2.6.3

  • Wordpress 2.6.5

  • Wordpress 2.7

  • Wordpress 2.7.1

  • Wordpress 2.8

  • Wordpress 2.8.1

  • Wordpress 2.8.2

  • Wordpress 2.8.3

  • Wordpress 2.8.4

  • Wordpress 2.8.5

  • Wordpress 2.8.5.1

  • Wordpress 2.8.5.2

  • Wordpress 2.8.6

  • Wordpress 2.9

  • Wordpress 2.9.1

  • Wordpress 2.9.1.1

  • Wordpress 2.9.2

  • Wordpress 3.0

  • Wordpress 3.0.1

  • Wordpress 3.0.2

  • Wordpress 3.0.3

  • Wordpress 3.0.4

  • Wordpress 3.0.5

  • Wordpress 3.0.6

  • Wordpress 3.1

  • Wordpress 3.1.1

  • Wordpress 3.1.2

  • Wordpress 3.1.3

  • Wordpress 3.1.4

  • Wordpress 3.2

  • Wordpress 3.2.1

  • Wordpress 3.3

  • Wordpress 3.3.2

  • Wordpress 3.3.3

  • Wordpress 3.4.0


References

MLIST - [oss-security] 20120707 Re: CVE #'s for WordPress 3.4.1 release

MLIST - [oss-security] 20120702 CVE #'s for WordPress 3.4.1 release

CONFIRM - http://codex.wordpress.org/Version_3.4.1


Last Updated: 27 May 2016 10:53:33