PT-2014-2060 · WordPress · Wordpress

Henri Salo

·

Published

2014-10-01

·

Updated

2017-08-29

·

CVE-2003-1598

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WordPress versions 0.7 and earlier
Description A SQL injection issue in the log.header.php file allows remote attackers to execute arbitrary SQL commands via the posts variable. This enables attackers to manipulate database queries, potentially leading to unauthorized data access or modification.
Recommendations For WordPress versions 0.7 and earlier, as a temporary workaround, consider restricting access to the log.header.php file or disabling the use of the posts variable in this context until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2003-1598

Affected Products

Wordpress