WordPress Comment Table SQL Injection Vulnerability
BID:21896
Info
WordPress Comment Table SQL Injection Vulnerability
| Bugtraq ID: | 21896 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2007 12:00AM |
| Updated: | Jan 05 2007 12:00AM |
| Credit: | Stefan Esser is credited with the discovery of this vulnerability. |
| Vulnerable: |
WordPress Wordpress (B2) 0.6.2 .1 WordPress Wordpress (B2) 0.6.2 WordPress WordPress 2.0.5 WordPress WordPress 2.0.4 WordPress WordPress 2.0.3 WordPress WordPress 2.0.2 WordPress WordPress 2.0.1 WordPress WordPress 2.0 WordPress WordPress 1.5.2 WordPress WordPress 1.5.1 .3 WordPress WordPress 1.5.1 .2 WordPress WordPress 1.5.1 WordPress WordPress 1.5 WordPress WordPress 1.2.2 WordPress WordPress 1.2.1 WordPress WordPress 1.2 WordPress WordPress 0.71 WordPress WordPress 0.7 |
| Not Vulnerable: |
WordPress WordPress 2.0.6 |
Discussion
WordPress Comment Table SQL Injection Vulnerability
WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
WordPress 2.0.5 and prior versions are vulnerable.
WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
WordPress 2.0.5 and prior versions are vulnerable.
Exploit / POC
WordPress Comment Table SQL Injection Vulnerability
An attacker can exploit this issue via a web client.
An attacker can exploit this issue via a web client.
Solution / Fix
WordPress Comment Table SQL Injection Vulnerability
Solution:
The vendor has released version 2.0.6 to address this issue; please see the reference section for details.
Solution:
The vendor has released version 2.0.6 to address this issue; please see the reference section for details.
References
WordPress Comment Table SQL Injection Vulnerability
References:
References: