[] NeoSense

WordPress Core 2.3.1 - Unauthorized Post Access

Author: Michael Brooks
type: webapps
platform: php
port: 
date_added: 2007-12-15 
date_updated: 2017-05-04 
verified: 1 
codes: OSVDB-39518 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comwordpress-2.3.1.zip

source: https://www.securityfocus.com/bid/26885/info

WordPress is prone to a vulnerability that lets unauthorized users read draft posts before they have been published.

This issue affects WordPress 2.3.1; other versions may also be affected.

NOTE: This BID is being reinstated because further investigation reveals that the application is vulnerable. The exploit URI supplied in the initial report was not sufficient to trigger the issue, which led to the vulnerability claim being refuted. However, follow-up information from the reporter included a URI that does trigger the issue.

http://www.example.com/wordpress/index.php/wp-admin/