Skip to content
Saturday, December 6, 2025
Medium Published: Jan 10, 2008 Modified: Apr 09, 2025

CVE-2008-0191

5 CVSS SCORE
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
Share:

Description

WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.

CVSS Vector Details

Attack Vector Network
Attack Complexity Low
Confidentiality P
Integrity None
Availability None

Affected Software Configurations

  • a wordpress wordpress 2.2 * * * * * * *
  • a wordpress wordpress 2.3 * * * * * * *

Weaknesses (CWE)

  • CWE-200