ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2014-5205”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2014-5205
Published
2014-08-18
CVSS:
-
ShadowTrackr CVSS:
0.0
Summary:
wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.