CVE-2008-4106

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.
References
Link Resource
http://marc.info/?l=oss-security&m=122152830017099&w=2
http://secunia.com/advisories/31737
http://secunia.com/advisories/31870 Vendor Advisory
http://securityreason.com/securityalert/4272
http://securitytracker.com/id?1020869
http://wordpress.org/development/2008/09/wordpress-262/ Patch
http://www.debian.org/security/2009/dsa-1871
http://www.openwall.com/lists/oss-security/2008/09/11/6
http://www.securityfocus.com/archive/1/496287/100/0/threaded
http://www.securityfocus.com/bid/31068
http://www.sektioneins.de/advisories/SE-2008-05.txt
http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/
http://www.vupen.com/english/advisories/2008/2553
https://www.exploit-db.com/exploits/6397
https://www.exploit-db.com/exploits/6421
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00607.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00629.html
http://marc.info/?l=oss-security&m=122152830017099&w=2
http://secunia.com/advisories/31737
http://secunia.com/advisories/31870 Vendor Advisory
http://securityreason.com/securityalert/4272
http://securitytracker.com/id?1020869
http://wordpress.org/development/2008/09/wordpress-262/ Patch
http://www.debian.org/security/2009/dsa-1871
http://www.openwall.com/lists/oss-security/2008/09/11/6
http://www.securityfocus.com/archive/1/496287/100/0/threaded
http://www.securityfocus.com/bid/31068
http://www.sektioneins.de/advisories/SE-2008-05.txt
http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/
http://www.vupen.com/english/advisories/2008/2553
https://www.exploit-db.com/exploits/6397
https://www.exploit-db.com/exploits/6421
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00607.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00629.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.71-gold:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0-platinum:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0.1-miles:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0.2-blakey:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2-delta:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2-mingus:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5-strayhorn:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.5:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:2.6:*:*:*:*:*:*:*

History

21 Nov 2024, 00:50

Type Values Removed Values Added
References () http://marc.info/?l=oss-security&m=122152830017099&w=2 - () http://marc.info/?l=oss-security&m=122152830017099&w=2 -
References () http://secunia.com/advisories/31737 - () http://secunia.com/advisories/31737 -
References () http://secunia.com/advisories/31870 - Vendor Advisory () http://secunia.com/advisories/31870 - Vendor Advisory
References () http://securityreason.com/securityalert/4272 - () http://securityreason.com/securityalert/4272 -
References () http://securitytracker.com/id?1020869 - () http://securitytracker.com/id?1020869 -
References () http://wordpress.org/development/2008/09/wordpress-262/ - Patch () http://wordpress.org/development/2008/09/wordpress-262/ - Patch
References () http://www.debian.org/security/2009/dsa-1871 - () http://www.debian.org/security/2009/dsa-1871 -
References () http://www.openwall.com/lists/oss-security/2008/09/11/6 - () http://www.openwall.com/lists/oss-security/2008/09/11/6 -
References () http://www.securityfocus.com/archive/1/496287/100/0/threaded - () http://www.securityfocus.com/archive/1/496287/100/0/threaded -
References () http://www.securityfocus.com/bid/31068 - () http://www.securityfocus.com/bid/31068 -
References () http://www.sektioneins.de/advisories/SE-2008-05.txt - () http://www.sektioneins.de/advisories/SE-2008-05.txt -
References () http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/ - () http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/ -
References () http://www.vupen.com/english/advisories/2008/2553 - () http://www.vupen.com/english/advisories/2008/2553 -
References () https://www.exploit-db.com/exploits/6397 - () https://www.exploit-db.com/exploits/6397 -
References () https://www.exploit-db.com/exploits/6421 - () https://www.exploit-db.com/exploits/6421 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00607.html - () https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00607.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00629.html - () https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00629.html -

Information

Published : 2008-09-18 17:59

Updated : 2024-11-21 00:50


NVD link : CVE-2008-4106

Mitre link : CVE-2008-4106

CVE.ORG link : CVE-2008-4106


JSON object : View

Products Affected

wordpress

  • wordpress
CWE
CWE-20

Improper Input Validation