Vulnerability Name: | CVE-2007-4154 (CCN-35719) | ||||||||||||||||
Assigned: | 2007-07-31 | ||||||||||||||||
Published: | 2007-07-31 | ||||||||||||||||
Updated: | 2017-07-29 | ||||||||||||||||
Summary: | SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbitrary SQL commands via the page_options parameter to (1) options-general.php, (2) options-writing.php, (3) options-reading.php, (4) options-discussion.php, (5) options-privacy.php, (6) options-permalink.php, (7) options-misc.php, and possibly other unspecified components. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 5.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
6.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2007-4154 Source: CCN Type: mybeNi websecurity blog: July 31st, 2007 2. Wordpress /options.php SQL Injection Vulnerability Source: MISC Type: UNKNOWN http://mybeni.rootzilla.de/mybeNi/2007/wordpress_zeroday_vulnerability_roundhouse_kick_and_why_i_nearly_wrote_the_first_blog_worm/ Source: SECUNIA Type: UNKNOWN 30013 Source: CCN Type: Wordpress trac Ticket #4690 Wordpress options.php SQL Injection Vulnerability Source: DEBIAN Type: UNKNOWN DSA-1564 Source: DEBIAN Type: DSA-1564 wordpress -- multiple vulnerabilities Source: CCN Type: OSVDB ID: 39371 Wordpress options-general.php page_options Parameter SQL Injection Source: CCN Type: OSVDB ID: 39372 Wordpress options-writing.php page_options Parameter SQL Injection Source: CCN Type: OSVDB ID: 39373 Wordpress options-reading.php page_options Parameter SQL Injection Source: CCN Type: OSVDB ID: 39374 Wordpress options-discussion.php page_options Parameter SQL Injection Source: CCN Type: OSVDB ID: 39375 Wordpress options-privacy.php page_options Parameter SQL Injection Source: CCN Type: OSVDB ID: 39376 Wordpress options-permalink.php page_options Parameter SQL Injection Source: CCN Type: OSVDB ID: 39377 Wordpress options-misc.php page_options Parameter SQL Injection Source: CCN Type: BID-25161 WordPress Multiple Input Validation Vulnerabilities Source: XF Type: UNKNOWN wordpress-options-sql-injection(35719) Source: XF Type: UNKNOWN wordpress-options-sql-injection(35719) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |