Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title Security update for wordpress
Informations
Name DSA-2138 First vendor Publication 2010-12-29
Vendor Debian Last vendor Modification 2010-12-29
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:S/C:P/I:P/A:P)
Cvss Base Score 6 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 6.8 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

Vladimir Kolesnikov discovered a SQL injection vulnerability in wordpress, a weblog manager. An authenticated users could execute arbitrary SQL commands via the Send Trackbacks field.

For the stable distribution (lenny), this problem has been fixed in version 2.5.1-11+lenny4.

For the unstable distribution (sid), and the testing distribution (squeeze), this problem has been fixed in version 3.0.2-1.

We recommend that you upgrade your wordpress package.

Original Source

Url : http://www.debian.org/security/2010/dsa-2138

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('SQL Injection') (CWE/SANS Top 25)

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:18452
 
Oval ID: oval:org.mitre.oval:def:18452
Title: DSA-2138-1 wordpress - SQL injection
Description: Vladimir Kolesnikov discovered a SQL injection vulnerability in WordPress, a weblog manager. An authenticated user could execute arbitrary SQL commands via the Send Trackbacks field.
Family: unix Class: patch
Reference(s): DSA-2138-1
CVE-2010-4257
Version: 7
Platform(s): Debian GNU/Linux 5.0
Product(s): wordpress
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 222

OpenVAS Exploits

Date Description
2011-03-07 Name : Debian Security Advisory DSA 2138-1 (wordpress)
File : nvt/deb_2138_1.nasl
2011-03-05 Name : FreeBSD Ports: wordpress
File : nvt/freebsd_wordpress12.nasl
2011-01-11 Name : Fedora Update for wordpress FEDORA-2010-19290
File : nvt/gb_fedora_2010_19290_wordpress_fc13.nasl
2011-01-11 Name : Fedora Update for wordpress FEDORA-2010-19296
File : nvt/gb_fedora_2010_19296_wordpress_fc14.nasl
2011-01-11 Name : Fedora Update for wordpress-mu FEDORA-2010-19329
File : nvt/gb_fedora_2010_19329_wordpress-mu_fc14.nasl
2011-01-11 Name : Fedora Update for wordpress-mu FEDORA-2010-19330
File : nvt/gb_fedora_2010_19330_wordpress-mu_fc13.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
69536 WordPress wp-includes/comment.php Send Trackbacks Field SQL Injection

WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the wp-includes/comment.php script not properly sanitizing user-supplied input to the 'Send Trackbacks' field. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.

Nessus® Vulnerability Scanner

Date Description
2011-02-06 Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_8c93e99730e011e0b300485d605f4717.nasl - Type : ACT_GATHER_INFO
2011-02-03 Name : The remote web server hosts a PHP application that is affected by multiple vu...
File : wordpress_3_0_2.nasl - Type : ACT_GATHER_INFO
2011-01-10 Name : The remote Fedora host is missing a security update.
File : fedora_2010-19329.nasl - Type : ACT_GATHER_INFO
2011-01-10 Name : The remote Fedora host is missing a security update.
File : fedora_2010-19330.nasl - Type : ACT_GATHER_INFO
2011-01-07 Name : The remote Fedora host is missing a security update.
File : fedora_2010-19290.nasl - Type : ACT_GATHER_INFO
2011-01-07 Name : The remote Fedora host is missing a security update.
File : fedora_2010-19296.nasl - Type : ACT_GATHER_INFO
2011-01-03 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2138.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 11:29:46
  • Multiple Updates