CVE-2011-4898
WordPress Core 3.3.1 - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective
** CONTROVERTIDO ** wp-admin/setup-config.php en el componente de instalación de WordPress v3.3.1 y anteriores genera diferentes mensajes de error para las solicitudes que carecen de un parámetro dbname dependiendo de si las credenciales MySQL son válidas, lo facilita a los atacantes remotos a la hora de llevar a cabo ataque de fuerza bruta a través de un gran numero de peticiones con diferentes parámetros 'uname' y 'pwd'. NOTA: el vendedor se opone a la importancia de este problema. Por otra parte, tampoco está claro si proporcionar mensajes de error intencionalmente vagos durante la instalación es razonable desde la perspectiva de la usabilidad.
WordPress versions 3.3.1 and below suffer from MySQL username/password disclosure, PHP code execution and cross site scripting vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-12-23 CVE Reserved
- 2012-01-25 CVE Published
- 2012-01-25 First Exploit
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/18417 | 2012-01-25 | |
http://archives.neohapsis.com/archives/bugtraq/2012-01/0150.html | 2024-09-16 | |
http://www.exploit-db.com/exploits/18417 | 2024-09-16 | |
https://www.trustwave.com/spiderlabs/advisories/TWSL2012-002.txt | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | <= 3.3.1 Search vendor "Wordpress" for product "Wordpress" and version " <= 3.3.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 0.7 Search vendor "Wordpress" for product "Wordpress" and version "0.7" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 0.71 Search vendor "Wordpress" for product "Wordpress" and version "0.71" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 0.72 Search vendor "Wordpress" for product "Wordpress" and version "0.72" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 0.711 Search vendor "Wordpress" for product "Wordpress" and version "0.711" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.0 Search vendor "Wordpress" for product "Wordpress" and version "1.0" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.0.1 Search vendor "Wordpress" for product "Wordpress" and version "1.0.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.0.2 Search vendor "Wordpress" for product "Wordpress" and version "1.0.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.2 Search vendor "Wordpress" for product "Wordpress" and version "1.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.2.1 Search vendor "Wordpress" for product "Wordpress" and version "1.2.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.2.2 Search vendor "Wordpress" for product "Wordpress" and version "1.2.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5 Search vendor "Wordpress" for product "Wordpress" and version "1.5" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5.1 Search vendor "Wordpress" for product "Wordpress" and version "1.5.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5.1.2 Search vendor "Wordpress" for product "Wordpress" and version "1.5.1.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5.1.3 Search vendor "Wordpress" for product "Wordpress" and version "1.5.1.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 1.5.2 Search vendor "Wordpress" for product "Wordpress" and version "1.5.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0 Search vendor "Wordpress" for product "Wordpress" and version "2.0" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.1 Search vendor "Wordpress" for product "Wordpress" and version "2.0.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.2 Search vendor "Wordpress" for product "Wordpress" and version "2.0.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.3 Search vendor "Wordpress" for product "Wordpress" and version "2.0.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.4 Search vendor "Wordpress" for product "Wordpress" and version "2.0.4" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.5 Search vendor "Wordpress" for product "Wordpress" and version "2.0.5" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.6 Search vendor "Wordpress" for product "Wordpress" and version "2.0.6" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.7 Search vendor "Wordpress" for product "Wordpress" and version "2.0.7" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.8 Search vendor "Wordpress" for product "Wordpress" and version "2.0.8" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.9 Search vendor "Wordpress" for product "Wordpress" and version "2.0.9" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.10 Search vendor "Wordpress" for product "Wordpress" and version "2.0.10" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.0.11 Search vendor "Wordpress" for product "Wordpress" and version "2.0.11" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.1 Search vendor "Wordpress" for product "Wordpress" and version "2.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.1.1 Search vendor "Wordpress" for product "Wordpress" and version "2.1.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.1.2 Search vendor "Wordpress" for product "Wordpress" and version "2.1.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.1.3 Search vendor "Wordpress" for product "Wordpress" and version "2.1.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.2 Search vendor "Wordpress" for product "Wordpress" and version "2.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.2.1 Search vendor "Wordpress" for product "Wordpress" and version "2.2.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.2.2 Search vendor "Wordpress" for product "Wordpress" and version "2.2.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.2.3 Search vendor "Wordpress" for product "Wordpress" and version "2.2.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.3 Search vendor "Wordpress" for product "Wordpress" and version "2.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.3.1 Search vendor "Wordpress" for product "Wordpress" and version "2.3.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.3.2 Search vendor "Wordpress" for product "Wordpress" and version "2.3.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.3.3 Search vendor "Wordpress" for product "Wordpress" and version "2.3.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.5 Search vendor "Wordpress" for product "Wordpress" and version "2.5" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.5.1 Search vendor "Wordpress" for product "Wordpress" and version "2.5.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.6 Search vendor "Wordpress" for product "Wordpress" and version "2.6" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.6.1 Search vendor "Wordpress" for product "Wordpress" and version "2.6.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.6.2 Search vendor "Wordpress" for product "Wordpress" and version "2.6.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.6.3 Search vendor "Wordpress" for product "Wordpress" and version "2.6.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.6.5 Search vendor "Wordpress" for product "Wordpress" and version "2.6.5" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.7 Search vendor "Wordpress" for product "Wordpress" and version "2.7" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.7.1 Search vendor "Wordpress" for product "Wordpress" and version "2.7.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.8 Search vendor "Wordpress" for product "Wordpress" and version "2.8" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.8.1 Search vendor "Wordpress" for product "Wordpress" and version "2.8.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.8.2 Search vendor "Wordpress" for product "Wordpress" and version "2.8.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.8.3 Search vendor "Wordpress" for product "Wordpress" and version "2.8.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.8.4 Search vendor "Wordpress" for product "Wordpress" and version "2.8.4" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.8.5 Search vendor "Wordpress" for product "Wordpress" and version "2.8.5" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.8.6 Search vendor "Wordpress" for product "Wordpress" and version "2.8.6" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.9 Search vendor "Wordpress" for product "Wordpress" and version "2.9" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.9.1 Search vendor "Wordpress" for product "Wordpress" and version "2.9.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 2.9.2 Search vendor "Wordpress" for product "Wordpress" and version "2.9.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.0 Search vendor "Wordpress" for product "Wordpress" and version "3.0" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.0.1 Search vendor "Wordpress" for product "Wordpress" and version "3.0.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.0.2 Search vendor "Wordpress" for product "Wordpress" and version "3.0.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.0.3 Search vendor "Wordpress" for product "Wordpress" and version "3.0.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.0.4 Search vendor "Wordpress" for product "Wordpress" and version "3.0.4" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.0.5 Search vendor "Wordpress" for product "Wordpress" and version "3.0.5" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.0.6 Search vendor "Wordpress" for product "Wordpress" and version "3.0.6" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.1 Search vendor "Wordpress" for product "Wordpress" and version "3.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.1.1 Search vendor "Wordpress" for product "Wordpress" and version "3.1.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.1.2 Search vendor "Wordpress" for product "Wordpress" and version "3.1.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.1.3 Search vendor "Wordpress" for product "Wordpress" and version "3.1.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.1.4 Search vendor "Wordpress" for product "Wordpress" and version "3.1.4" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.2.1 Search vendor "Wordpress" for product "Wordpress" and version "3.2.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.3 Search vendor "Wordpress" for product "Wordpress" and version "3.3" | - |
Affected
|