Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-4899
HistoryJan 30, 2012 - 12:00 a.m.

CVE-2011-4899

2012-01-3000:00:00
ubuntu.com
ubuntu.com
12

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.038

Percentile

92.0%

DISPUTED wp-admin/setup-config.php in the installation component in
WordPress 3.3.1 and earlier does not ensure that the specified MySQL
database service is appropriate, which allows remote attackers to configure
an arbitrary database via the dbhost and dbname parameters, and
subsequently conduct static code injection and cross-site scripting (XSS)
attacks via (1) an HTTP request or (2) a MySQL query. NOTE: the vendor
disputes the significance of this issue; however, remote code execution
makes the issue important in many realistic environments.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.038

Percentile

92.0%