Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-0937
HistoryJan 30, 2012 - 12:00 a.m.

CVE-2012-0937

2012-01-3000:00:00
ubuntu.com
ubuntu.com
10

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.005 Low

EPSS

Percentile

76.9%

DISPUTED wp-admin/setup-config.php in the installation component in
WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent
to external MySQL database servers, which allows remote attackers to use
WordPress as a proxy for brute-force attacks or denial of service attacks
via the dbhost parameter, a different vulnerability than CVE-2011-4898.
NOTE: the vendor disputes the significance of this issue because an
incomplete WordPress installation might be present on the network for only
a short time.

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.005 Low

EPSS

Percentile

76.9%