CVE Database
/

CVE-2008-4106

Back to search

CVE-2008-4106

Published: Sep 18, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.

VendorProductVersions

n/a

n/a

affected
n/a

References

31737
third-party-advisory
x_refsource_SECUNIA
6421
exploit
x_refsource_EXPLOIT-DB
ADV-2008-2553
vdb-entry
x_refsource_VUPEN
6397
exploit
x_refsource_EXPLOIT-DB
DSA-1871
vendor-advisory
x_refsource_DEBIAN
4272
third-party-advisory
x_refsource_SREASON
31068
vdb-entry
x_refsource_BID
31870
third-party-advisory
x_refsource_SECUNIA
1020869
vdb-entry
x_refsource_SECTRACK
FEDORA-2008-7902
vendor-advisory
x_refsource_FEDORA
FEDORA-2008-7760
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now