Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress 信息泄露漏洞
Vulnerability Description
WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress 4.2.3及之前版本的wp-includes/class-wp-customize-widgets.php脚本中的‘sanitize_widget_instance’函数存在安全漏洞,该漏洞源于程序没有对widget使用constant-time对比方法。远程攻击者可通过在计算出差异之前测量延迟利用该漏洞实施时序旁路攻击。
CVSS Information
N/A
Vulnerability Type
N/A