|
|
| |
|
| |
wordpress: arbitrary command execution
| Package(s): | wordpress |
CVE #(s): | CVE-2006-2667
CVE-2006-2702
|
| Created: | June 12, 2006 |
Updated: | June 14, 2006 |
| Description: |
WordPress insufficiently checks the format of cached username data. An
attacker could exploit this vulnerability to execute arbitrary commands by
sending a specially crafted username. As of Wordpress 2.0.2 the user data
cache is disabled as the default. |
| Alerts: |
|
( Log in to post comments)
|
|
|