PT-2012-1989 · WordPress+1 · Wordpress+1

CVE-2011-4899

·

Publicado

2012-01-30

·

Atualizado

2024-08-07

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WordPress versions 3.3.1 and earlier
Description The installation component in WordPress does not ensure that the specified MySQL database service is appropriate, allowing remote attackers to configure an arbitrary database via the dbhost and dbname parameters. This can lead to static code injection and cross-site scripting (XSS) attacks via an HTTP request or a MySQL query. The vendor disputes the significance of this issue, but remote code execution makes it important in many realistic environments.
Recommendations For WordPress versions 3.3.1 and earlier, as a temporary workaround, consider restricting access to the wp-admin/setup-config.php installation component to minimize the risk of exploitation. Avoid using the dbhost and dbname parameters in the affected installation component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2011-4899

Produtos afetados

Debian
Wordpress