Opened 17 years ago
Closed 16 years ago
#10735 closed defect (bug) (wontfix)
CVE-2008-6767 patch: Only admin can upgrade wordpress
| Reported by: | Derevko | Owned by: | |
|---|---|---|---|
| Priority: | normal | Milestone: | |
| Component: | Upgrade/Install | Version: | |
| Severity: | normal | Keywords: | |
| Cc: | Focuses: |
Description
Hi,
with the trivial attached patch I fixed CVE-2008-6767 in wordpress debian package:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6767
Attachments (1)
Change History (5)
#1
follow-up:
↓ 2
@
17 years ago
- Keywords has-patch added
- Milestone Unassigned → 2.9
You should use 'administrator' instead of 'level_10'.
#2
in reply to: ↑ 1
@
17 years ago
Replying to scribu:
You should use 'administrator' instead of 'level_10'.
The original patch did have 'administrator', but a user point me the fact that sometimes the administrator default account could not exist or renamed for security hardening
Note:
See TracTickets
for help on using tickets.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)
Only admin can upgrade wordpress. (CVE-2008-6767)