|
|
Log in / Subscribe / Register

wordpress: password vulnerability

Package(s):wordpress CVE #(s):CVE-2008-4106
Created:August 27, 2009 Updated:September 2, 2009
Description: From the National Vulnerability Database entry: "WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability.""
Alerts:
Debian DSA-1871-2 wordpress 2009-08-27

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds