oss-sec mailing list archives

CVE-request: WordPress SQL injection and arbitrary code injection (2003)


From: Henri Salo <henri () nerv fi>
Date: Tue, 3 Jan 2012 23:41:28 +0200

These two WordPress security vulnerabilities from 2003 are still without CVE-identifiers. I am requesting 
CVE-identifiers as these issues have highly critical impact.

1) SQL injection
http://osvdb.org/show/osvdb/4610

2) Arbitrary code injection
http://osvdb.org/show/osvdb/4611

Secunia advisory: http://secunia.com/advisories/8954/

- Henri Salo


Current thread: