Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6318 (WordPress)

BugsAlert Home > CVE-2007-6318 (WordPress)
 
 

SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a multibyte character.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6318

Learn more about CVE-2007-6318 (WordPress)
 
Tags: cve-2007-6318 wordpress

Related Items

      CVE-2008-4649 (elxis_cms)

      FrSIRT - GLib PCRE "pcre_compile.c" Patterns Buffer Overflow Vulnerability

      CVE-2008-2464 (freebsd, kame, netbsd)

      FrSIRT - Mandriva Security Update Fixes Tk "ReadImage()" Buffer Overflow Issue

      CVE-2008-4095 (flip4mac_wmv)

      Multiple vulnerabilities in SAPlpd 6.28

      CVE-2008-0681 (phpShop)

 

Pixel