Files
CVEs-PoC/2008/CVE-2008-2146.md
2025-09-29 21:09:30 +02:00

690 B

CVE-2008-2146

Description

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

POC

Reference

Github