CVE-2007-6013

Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-11-19 21:46

Updated : 2024-02-09 03:15


NVD link : CVE-2007-6013

Mitre link : CVE-2007-6013

CVE.ORG link : CVE-2007-6013


JSON object : View

Products Affected

fedoraproject

  • fedora

wordpress

  • wordpress
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm