Total vulnerabilities in the database
wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.
Software | From | Fixed in |
---|---|---|
WordPress / wordpress | 2.0 | 2.0.x |
WordPress / wordpress | 2.0.2 | 2.0.2.x |
WordPress / wordpress | 2.0.1 | 2.0.1.x |
WordPress / wordpress | 2.0.4 | 2.0.4.x |
WordPress / wordpress | 2.0.5 | 2.0.5.x |
WordPress / wordpress | 2.0.3 | 2.0.3.x |