Lucene search

K
nvd[email protected]NVD:CVE-2008-4106
HistorySep 18, 2008 - 5:59 p.m.

CVE-2008-4106

2008-09-1817:59:33
CWE-20
web.nvd.nist.gov
6

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.014

Percentile

86.5%

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user’s password to a random value by registering a similar username and then requesting a password reset, related to a “SQL column truncation vulnerability.” NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.

Affected configurations

Nvd
Node
wordpresswordpressRange2.6.1
OR
wordpresswordpressMatch0.71-gold
OR
wordpresswordpressMatch1.0-platinum
OR
wordpresswordpressMatch1.0.1-miles
OR
wordpresswordpressMatch1.0.2-blakey
OR
wordpresswordpressMatch1.2-delta
OR
wordpresswordpressMatch1.2-mingus
OR
wordpresswordpressMatch1.2.1
OR
wordpresswordpressMatch1.2.2
OR
wordpresswordpressMatch1.5-strayhorn
OR
wordpresswordpressMatch1.5.1.1
OR
wordpresswordpressMatch1.5.1.2
OR
wordpresswordpressMatch1.5.1.3
OR
wordpresswordpressMatch1.5.2
OR
wordpresswordpressMatch2.0
OR
wordpresswordpressMatch2.0.1
OR
wordpresswordpressMatch2.0.4
OR
wordpresswordpressMatch2.0.5
OR
wordpresswordpressMatch2.0.6
OR
wordpresswordpressMatch2.0.7
OR
wordpresswordpressMatch2.0.9
OR
wordpresswordpressMatch2.0.10
OR
wordpresswordpressMatch2.0.11
OR
wordpresswordpressMatch2.1
OR
wordpresswordpressMatch2.1.1
OR
wordpresswordpressMatch2.1.2
OR
wordpresswordpressMatch2.1.3
OR
wordpresswordpressMatch2.2
OR
wordpresswordpressMatch2.2.1
OR
wordpresswordpressMatch2.2.2
OR
wordpresswordpressMatch2.2.3
OR
wordpresswordpressMatch2.5
OR
wordpresswordpressMatch2.5.1
OR
wordpresswordpressMatch2.6
VendorProductVersionCPE
wordpresswordpress*cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
wordpresswordpress0.71-goldcpe:2.3:a:wordpress:wordpress:0.71-gold:*:*:*:*:*:*:*
wordpresswordpress1.0-platinumcpe:2.3:a:wordpress:wordpress:1.0-platinum:*:*:*:*:*:*:*
wordpresswordpress1.0.1-milescpe:2.3:a:wordpress:wordpress:1.0.1-miles:*:*:*:*:*:*:*
wordpresswordpress1.0.2-blakeycpe:2.3:a:wordpress:wordpress:1.0.2-blakey:*:*:*:*:*:*:*
wordpresswordpress1.2-deltacpe:2.3:a:wordpress:wordpress:1.2-delta:*:*:*:*:*:*:*
wordpresswordpress1.2-minguscpe:2.3:a:wordpress:wordpress:1.2-mingus:*:*:*:*:*:*:*
wordpresswordpress1.2.1cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
wordpresswordpress1.2.2cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
wordpresswordpress1.5-strayhorncpe:2.3:a:wordpress:wordpress:1.5-strayhorn:*:*:*:*:*:*:*
Rows per page:
1-10 of 341

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.014

Percentile

86.5%