LWN.net Logo

wordpress: SQL injection

Package(s):wordpress CVE #(s):CVE-2010-4257
Created:December 29, 2010 Updated:January 10, 2011
Description:

From the Debian advisory:

Vladimir Kolesnikov discovered a SQL injection vulnerability in wordpress, a weblog manager. An authenticated users could execute arbitrary SQL commands via the Send Trackbacks field.

Alerts:
Fedora FEDORA-2010-19330 2010-12-31
Fedora FEDORA-2010-19329 2010-12-31
Fedora FEDORA-2010-19290 2010-12-29
Fedora FEDORA-2010-19296 2010-12-29
Debian DSA-2138-1 2010-12-29

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds