PT-2012-1988 · WordPress+1 · Wordpress+1
Published
2012-01-30
·
Updated
2024-08-07
·
CVE-2011-4898
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
WordPress versions 3.3.1 and earlier
Description
The installation component in WordPress generates different error messages for requests lacking a
dbname parameter depending on whether the MySQL credentials are valid. This makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. The vendor disputes the significance of this issue, and it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective.Recommendations
For WordPress versions 3.3.1 and earlier, consider restricting access to the
wp-admin/setup-config.php installation component to minimize the risk of exploitation. As a temporary workaround, avoid using the uname and pwd parameters in the affected requests until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Wordpress