Total vulnerabilities in the database
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Software | From | Fixed in |
---|---|---|
WordPress / wordpress | 1.5 | 2.3.1.x |
fedoraproject / fedora | 8 | 8.x |
fedoraproject / fedora | 7 | 7.x |