Wordpress Cat_ID Parameter SQL Injection Vulnerability
BID:13809
Info
Wordpress Cat_ID Parameter SQL Injection Vulnerability
| Bugtraq ID: | 13809 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1810 |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | The individual or individuals responsible for the discovery of this issue are currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
WordPress WordPress 1.5.1 WordPress WordPress 1.5 Gentoo Linux |
| Not Vulnerable: |
WordPress WordPress 1.5.1 .2 |
Discussion
Wordpress Cat_ID Parameter SQL Injection Vulnerability
Wordpress is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Wordpress is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Wordpress Cat_ID Parameter SQL Injection Vulnerability
No exploit is required.
"Alberto Trivero" <[email protected]> has supplied the wordpress-sql-inj.pl exploit.
1dt.w0lf has provided the wordpress1511newadmin.pl exploit.
No exploit is required.
"Alberto Trivero" <[email protected]> has supplied the wordpress-sql-inj.pl exploit.
1dt.w0lf has provided the wordpress1511newadmin.pl exploit.
Solution / Fix
Wordpress Cat_ID Parameter SQL Injection Vulnerability
Solution:
The vendor has addressed this issue in Wordpress version 1.5.1.2:
Gentoo has released advisory GLSA 200506-04 to address this issue. Please see the referenced advisory for more information. Gentoo users may update their computers by carrying out the following commands:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/wordpress-1.5.1.2"
WordPress WordPress 1.5
WordPress WordPress 1.5.1
Solution:
The vendor has addressed this issue in Wordpress version 1.5.1.2:
Gentoo has released advisory GLSA 200506-04 to address this issue. Please see the referenced advisory for more information. Gentoo users may update their computers by carrying out the following commands:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/wordpress-1.5.1.2"
WordPress WordPress 1.5
-
WordPress WordPress Latest Release Download
http://wordpress.org/latest.tar.gz
WordPress WordPress 1.5.1
-
WordPress WordPress Latest Release Download
http://wordpress.org/latest.tar.gz
References
Wordpress Cat_ID Parameter SQL Injection Vulnerability
References:
References:
- WordPress Homepage (WordPress)
- WordPress Security Update May 5 2005 (WordPress)
- Multiple CMS/Forum Vulnablilties (pacifico)
- SQL Injection Exploit for WordPress <= 1.5.1.1 ("Alberto Trivero"
)