PT-2014-2060 · WordPress · Wordpress

Henri Salo

·

Publicado

2014-10-01

·

Atualizado

2017-08-29

·

CVE-2003-1598

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WordPress versions 0.7 and earlier
Description A SQL injection issue in the log.header.php file allows remote attackers to execute arbitrary SQL commands via the posts variable. This enables attackers to manipulate database queries, potentially leading to unauthorized data access or modification.
Recommendations For WordPress versions 0.7 and earlier, as a temporary workaround, consider restricting access to the log.header.php file or disabling the use of the posts variable in this context until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2003-1598

Produtos afetados

Wordpress