CVE-2012-0937
Summary
| CVE | CVE-2012-0937 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-01-30 17:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks or denial of service attacks via the dbhost parameter, a different vulnerability than CVE-2011-4898. NOTE: the vendor disputes the significance of this issue because an incomplete WordPress installation might be present on the network for only a short time |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wordpress | Wordpress | 0.7 | All | All | All |
| Application | Wordpress | Wordpress | 0.71 | All | All | All |
| Application | Wordpress | Wordpress | 0.711 | All | All | All |
| Application | Wordpress | Wordpress | 0.72 | All | All | All |
| Application | Wordpress | Wordpress | 1.0 | All | All | All |
| Application | Wordpress | Wordpress | 1.0.1 | All | All | All |
| Application | Wordpress | Wordpress | 1.0.2 | All | All | All |
| Application | Wordpress | Wordpress | 1.2 | All | All | All |
| Application | Wordpress | Wordpress | 1.2.1 | All | All | All |
| Application | Wordpress | Wordpress | 1.2.2 | All | All | All |
| Application | Wordpress | Wordpress | 1.5 | All | All | All |
| Application | Wordpress | Wordpress | 1.5.1 | All | All | All |
| Application | Wordpress | Wordpress | 1.5.1.2 | All | All | All |
| Application | Wordpress | Wordpress | 1.5.1.3 | All | All | All |
| Application | Wordpress | Wordpress | 1.5.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.0 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.10 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.11 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.4 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.5 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.6 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.7 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.8 | All | All | All |
| Application | Wordpress | Wordpress | 2.0.9 | All | All | All |
| Application | Wordpress | Wordpress | 2.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.1.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.1.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.1.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.2.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.2.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.2.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.3.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.3.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.3.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.5 | All | All | All |
| Application | Wordpress | Wordpress | 2.5.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.6 | All | All | All |
| Application | Wordpress | Wordpress | 2.6.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.6.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.6.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.6.5 | All | All | All |
| Application | Wordpress | Wordpress | 2.7 | All | All | All |
| Application | Wordpress | Wordpress | 2.7.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.8 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.2 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.3 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.4 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.5 | All | All | All |
| Application | Wordpress | Wordpress | 2.8.6 | All | All | All |
| Application | Wordpress | Wordpress | 2.9 | All | All | All |
| Application | Wordpress | Wordpress | 2.9.1 | All | All | All |
| Application | Wordpress | Wordpress | 2.9.2 | All | All | All |
| Application | Wordpress | Wordpress | 3.0 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.1 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.2 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.3 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.4 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.5 | All | All | All |
| Application | Wordpress | Wordpress | 3.0.6 | All | All | All |
| Application | Wordpress | Wordpress | 3.1 | All | All | All |
| Application | Wordpress | Wordpress | 3.1.1 | All | All | All |
| Application | Wordpress | Wordpress | 3.1.2 | All | All | All |
| Application | Wordpress | Wordpress | 3.1.3 | All | All | All |
| Application | Wordpress | Wordpress | 3.1.4 | All | All | All |
| Application | Wordpress | Wordpress | 3.2.1 | All | All | All |
| Application | Wordpress | Wordpress | 3.3 | All | All | All |
| Application | Wordpress | Wordpress | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 Not Found | Trustwave | af854a3a-2127-422b-91ae-364da2661108 | www.trustwave.com | |
| WordPress <= 3.3.1 Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.