MEDIUM
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters
Published Jan 30, 2012
5.0
MEDIUMCVSS 2.0
EPSS 9.21%
Description
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective
Affected products
No data.
OR
- ≤ 3.3.1
- 0.7
- 0.71
- 0.72
- 0.711
- 1.0
- 1.0.1
- 1.0.2
- 1.2
- 1.2.1
- 1.2.2
- 1.5
- 1.5.1
- 1.5.1.2
- 1.5.1.3
- 1.5.2
- 2.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
- 2.0.10
- 2.0.11
- 2.1
- 2.1.1
- 2.1.2
- 2.1.3
- 2.2
- 2.2.1
- 2.2.2
- 2.2.3
- 2.3
- 2.3.1
- 2.3.2
- 2.3.3
- 2.5
- 2.5.1
- 2.6
- 2.6.1
- 2.6.2
- 2.6.3
- 2.6.5
- 2.7
- 2.7.1
- 2.8
- 2.8.1
- 2.8.2
- 2.8.3
- 2.8.4
- 2.8.5
- 2.8.6
- 2.9
- 2.9.1
- 2.9.2
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.1
- 3.1.1
- 3.1.2
- 3.1.3
- 3.1.4
- 3.2.1
- 3.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://archives.neohapsis.com/archives/bugtraq/2012-01/0150.html mailing-listx_refsource_BUGTRAQExploit
- http://www.exploit-db.com/exploits/18417 exploitx_refsource_EXPLOIT-DB
- https://www.trustwave.com/spiderlabs/advisories/TWSL2012-002.txt x_refsource_MISCExploit
| Link | Providers | Tags |
|---|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2012-01/0150.html | mailing-listx_refsource_BUGTRAQExploit | |
| http://www.exploit-db.com/exploits/18417 | exploitx_refsource_EXPLOIT-DB | |
| https://www.trustwave.com/spiderlabs/advisories/TWSL2012-002.txt | x_refsource_MISCExploit |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 30, 2012
Updated Sep 16, 2024
Reserved Dec 23, 2011
Link CVE-2011-4898
CISA Vulnrichment
Updated n/a