Wordpress Posts SQL Injection Vulnerability
BID:7784
Info
Wordpress Posts SQL Injection Vulnerability
| Bugtraq ID: | 7784 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-1598 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2003 12:00AM |
| Updated: | Jan 06 2012 10:00PM |
| Credit: | Discovery of this vulnerability has been credited to [email protected]. |
| Vulnerable: |
WordPress WordPress 0.7 |
| Not Vulnerable: | |
Discussion
Wordpress Posts SQL Injection Vulnerability
Wordpress has been reported prone to an SQL injection vulnerability.
Wordpress does not properly sanitize user input that is passed to the 'posts' variable. An attacker may exploit this issue to insert SQL code into requests and have the SQL code executed by the underlying database server.
It should be noted that although this vulnerability has been reported to affect Wordpress version 0.7, other versions might also be affected.
Wordpress has been reported prone to an SQL injection vulnerability.
Wordpress does not properly sanitize user input that is passed to the 'posts' variable. An attacker may exploit this issue to insert SQL code into requests and have the SQL code executed by the underlying database server.
It should be noted that although this vulnerability has been reported to affect Wordpress version 0.7, other versions might also be affected.
Exploit / POC
Wordpress Posts SQL Injection Vulnerability
This vulnerability may be exploiting using a web browser.
This vulnerability may be exploiting using a web browser.
Solution / Fix
Wordpress Posts SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Wordpress Posts SQL Injection Vulnerability
References:
References:
- WordPress 0.7 (FraMe (frame at kernelpanik.org))
- WordPress Homepage (WordPress)