WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2014-11-25 23:59
Updated : 2016-06-30 16:58
NVD link : CVE-2014-9037
Mitre link : CVE-2014-9037
CVE.ORG link : CVE-2014-9037
JSON object : View
Products Affected
debian
- debian_linux
mageia_project
- mageia
wordpress
- wordpress
CWE
CWE-310
Cryptographic Issues