[Bug 716641] [NEW] CVE-2010-4257: SQL Injection from trackback functions

Launchpad Bug Tracker 716641 at bugs.launchpad.net
Fri Feb 11 16:26:05 UTC 2011


*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Mahyuddin Susanto (udienz):

Binary package hint: wordpress

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote
authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

** Affects: wordpress (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: wordpress (Debian)
     Importance: Unknown
         Status: Unknown

** Affects: wordpress (Fedora)
     Importance: Unknown
         Status: Unknown


** Tags: patch
-- 
CVE-2010-4257: SQL Injection from trackback functions
https://bugs.launchpad.net/bugs/716641
You received this bug notification because you are a member of Ubuntu Sponsors Team, which is a direct subscriber.



More information about the Ubuntu-sponsors mailing list