Lucene search

K
patchstackHanno BΓΆckPATCHSTACK:DAAF66A7B8424DB4E69ED068D85CF92C
HistorySep 15, 2008 - 12:00 a.m.

WordPress <= 2.6.1 - SQL Truncation Vulnerability #2

2008-09-1500:00:00
Hanno BΓΆck
patchstack.com
14

EPSS

0.013

Percentile

86.0%

The attackers can change an arbitrary user’s password to a random value by registering a similar username and then requesting a password reset, related to a β€œSQL column truncation vulnerability.”, because this WordPress does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames.

Solution

           Update WordPress. 

EPSS

0.013

Percentile

86.0%

Related for PATCHSTACK:DAAF66A7B8424DB4E69ED068D85CF92C