Wordpress Multiple Cross-Site Scripting and SQL Injection Vulnerabilities

BID:12066

Info

Wordpress Multiple Cross-Site Scripting and SQL Injection Vulnerabilities

Bugtraq ID: 12066
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Dec 21 2004 12:00AM
Updated: Dec 21 2004 12:00AM
Credit: These issues were reported by Thomas Waldegger <[email protected]>.
Vulnerable: WordPress WordPress 1.2.2
WordPress WordPress 1.2.1
+ Gentoo Linux
Not Vulnerable: WordPress WordPress 1.5.1

Discussion

Wordpress Multiple Cross-Site Scripting and SQL Injection Vulnerabilities

Wordpress is reported prone to multiple cross-site scripting and SQL injection vulnerabilities. These issues arise due to insufficient sanitization of user-supplied data.

These issues were previously reported in Wordpress Multiple Cross-Site Scripting, HTML Injection, And SQL Injection Vulnerabilities (BID 11984). Subsequent to the release of BID 11984, the vendor released Wordpress 1.2.2 to address the issues.

It is reported that Wordpress 1.2.2 does not address all the issues specified in that BID and it is still vulnerable to some cross-site scripting and SQL injection issues.

Exploit / POC

Wordpress Multiple Cross-Site Scripting and SQL Injection Vulnerabilities

An exploit is not required.

The following proof of concept examples are available:

Cross-site Scripting:
/wp-login.php?action=login&redirect_to=[XSS]
/wp-admin/templates.php?file=[XSS]
/wp-admin/post.php?content=[XSS]

SQL Injection:
/index.php?m=bla
/wp-admin/edit.php?m=bla

Solution / Fix

Wordpress Multiple Cross-Site Scripting and SQL Injection Vulnerabilities

Solution:
New information suggests the vendor has addressed these issues in WordPress version 1.5.1.


WordPress WordPress 1.2.1

WordPress WordPress 1.2.2

References

Wordpress Multiple Cross-Site Scripting and SQL Injection Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report